Key Takeaways
- The Government Accountability Office (GAO) found that the Federal Aviation Administration (FAA) has defined cybersecurity roles, while the Transportation Security Administration (TSA) lacks clear responsibilities and relies on an outdated 2018 cybersecurity roadmap.
- FAA’s budget submissions to the Office of Management and Budget (OMB) omitted cybersecurity program costs, weakening transparency and oversight.
- Although FAA’s aircraft‑certification procedures align with federal and industry standards, its Zero Trust Implementation Plan is incomplete, meeting only three of seven NIST practices.
- FAA has fully achieved only three of seven objectives supporting its cybersecurity strategy’s goal of protecting networks and systems.
- GAO issued five concrete recommendations: TSA should update its roadmap and define roles; FAA must improve budget reporting, revise its zero‑trust plan, and ensure its Cybersecurity Steering Committee performs scheduled monitoring.
- Both the Department of Homeland Security (DHS) and the Department of Transportation agreed with the recommendations directed to their respective agencies.
- The findings emerge as the Trump administration pushes broader federal cybersecurity initiatives and as DHS ramps up investments in border security, AI, and cyber defense—topics slated for discussion at the Potomac Officers Club’s 2026 Homeland Security Summit.
Overview of GAO Findings on Aviation Cybersecurity
In a report released Thursday, the Government Accountability Office evaluated the cybersecurity posture of the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA). GAO concluded that while the FAA has articulated the entities responsible for executing its cybersecurity goals, the TSA has not established comparable, clearly defined responsibilities. Moreover, TSA’s guiding document—the 2018 Cybersecurity Roadmap—remains outdated and does not reflect the latest Department of Homeland Security Cybersecurity Strategy. These shortcomings come at a time when the Trump administration is advancing broader cybersecurity initiatives aimed at securing federal systems and critical infrastructure, underscoring the urgency of addressing the identified gaps.
FAA’s Defined Cybersecurity Roles and Responsibilities
The GAO review noted that the FAA has taken steps to delineate who within the agency is accountable for various cybersecurity functions. By outlining the roles of specific offices and personnel, the FAA aims to create a clear chain of responsibility for implementing its cybersecurity objectives. This structural clarity is intended to facilitate coordination, streamline decision‑making, and ensure that accountability can be traced when security incidents occur. The existence of such role definitions places the FAA ahead of the TSA in terms of governance, although the GAO also identified areas where the FAA’s execution falls short of its planned framework.
TSA’s Lack of Clear Cybersecurity Responsibilities and Outdated Roadmap
In contrast to the FAA, the TSA has not formally assigned cybersecurity duties to particular organizational units or individuals. This ambiguity hampers effective oversight, risk assessment, and incident response within the agency responsible for securing the nation’s transportation systems. Additionally, the TSA continues to rely on a cybersecurity roadmap published in 2018, which GAO found to be obsolete. The roadmap does not incorporate current threat intelligence, evolving best practices, or the updated DHS Cybersecurity Strategy, leaving the TSA without a modern, actionable plan to guide its cybersecurity investments and priorities.
FAA’s Budget Reporting Shortfalls
GAO discovered that the FAA’s fiscal year 2024‑2026 budget data submitted to the Office of Management and Budget omitted several cybersecurity‑related activities and associated costs. Notably, the agency failed to include spending figures for its Information Security/Cybersecurity Program, which covers research and development work aimed at advancing defensive technologies. By excluding these line items, the FAA’s budget submission presents an incomplete picture of its cybersecurity resource allocation, impeding OMB’s ability to evaluate funding adequacy and limiting congressional oversight. Accurate budgeting is essential for justifying expenditures, tracking performance, and ensuring that sufficient resources are devoted to protecting aviation‑critical systems.
FAA’s Alignment with Federal and Industry Standards for Aircraft Certification
Despite the budgeting gaps, the GAO found that the FAA’s procedures for certifying aircraft and authorizing system security are consistent with applicable federal regulations and industry standards designed to mitigate cybersecurity threats to avionics and ground‑based systems. These alignment efforts help ensure that new aircraft entering service meet baseline security requirements and that existing fleets undergo appropriate assessments. The adherence to recognized standards provides a foundation for reducing vulnerabilities that could be exploited by adversaries seeking to compromise flight safety or disrupt air traffic operations.
Shortcomings in FAA’s Zero Trust Implementation Plan
The watchdog, the GAO evaluated the FAA’s Zero Trust Implementation Plan against seven National Institute of Standards and Technology (NIST) practices identified as essential for a robust zero‑trust architecture. The plan satisfied only three of those practices, primarily lacking detailed transition steps for the agency’s research and development (R&D) operating environment. Without a clear roadmap for migrating legacy systems, applying micro‑segmentation, enforcing least‑privilege access, and continuously monitoring trust levels, the FAA’s zero‑trust initiative remains partially implemented, leaving gaps that could be exploited by sophisticated cyber adversaries.
Partial Implementation of FAA’s Cybersecurity Strategy Objectives
GAO also assessed the FAA’s progress toward the seven objectives outlined in its cybersecurity strategy that support the overarching goal of protecting and defending its networks and systems. The agency had fully carried out only three of those objectives. The unmet objectives likely involve areas such as continuous monitoring, incident response maturation, and the integration of cybersecurity considerations into acquisition processes. Partial achievement indicates that while the FAA has made strides, substantial work remains to embed cybersecurity comprehensively across all mission‑critical functions.
GAO’s Five Recommendations for Improvement
To address the identified deficiencies, GAO issued five specific recommendations:
- TSA should update its Cybersecurity Roadmap to reflect current threats, align with the DHS Cybersecurity Strategy, and explicitly define cybersecurity roles and responsibilities throughout the agency.
- FAA must strengthen its budget reporting process to ensure that all cybersecurity activities and associated costs—including those for the Information Security/Cybersecurity Program—are transparently disclosed in submissions to OMB.
- FAA should revise its Zero Trust Implementation Plan to incorporate detailed transition steps for the R&D environment, thereby meeting all seven NIST zero‑trust practices.
- FAA needs to guarantee that its Cybersecurity Steering Committee executes its monitoring duties as prescribed, providing regular oversight of cybersecurity risk management initiatives.
- Both agencies should establish measurable performance metrics and timelines to track progress toward fulfilling the recommendations, enabling accountability and continuous improvement.
Agency Responses and Agreement to Recommendations
The Department of Homeland Security, which oversees TSA, and the Department of Transportation, which oversees the FAA, both concurred with the recommendations directed to their respective components. Their agreement signals a willingness to allocate resources, revise policies, and implement the necessary changes to close the identified gaps. By accepting the GAO’s findings, the agencies pave the way for improved governance, better budgetary transparency, and a more resilient cybersecurity posture across the aviation sector.
Implications for Upcoming Homeland Security Summit and Broader Cybersecurity Initiatives
The GAO report surfaces amid heightened federal focus on cybersecurity, with the Trump administration advancing initiatives to safeguard critical infrastructure and the DHS expanding investments in border security, artificial intelligence, and cyber defense. These developments will be central topics at the Potomac Officers Club’s 2026 Homeland Security Summit on November 12, where agency leaders and industry executives will discuss forthcoming strategies, technology adoption, and collaborative approaches to securing aviation and transportation systems. The summit offers a platform for the FAA and TSA to showcase progress on the GAO recommendations, share lessons learned, and align their efforts with national cybersecurity priorities. Effective implementation of the recommended actions will not only address the current oversight gaps but also strengthen the nation’s ability to defend against evolving cyber threats to aviation safety and operational continuity.

