Key Takeaways
- The FAA has only fully implemented three of seven network‑protection objectives from its 2020 Cybersecurity Strategy, lagging in monitoring, access controls, NIST alignment, and zero‑trust architecture.
- GAO criticizes the FAA for lacking a comprehensive process to track and evaluate goal implementation, hindering real‑time cyber monitoring for 35 systems.
- The FAA’s zero‑trust migration plan is incomplete: it omits research‑and‑development systems, fails to describe asset identification and management, and does not include effectiveness monitoring of the zero‑trust algorithm.
- The TSA has not defined its cybersecurity responsibilities or identified the offices/teams needed to carry them out, creating confusion among aviation stakeholders.
- Stakeholders doubt the TSA’s resources, authority, and expertise; 2023 regulations added uncertainty until a 2024 law clarified that the FAA holds exclusive authority to issue cybersecurity rules for civil aircraft.
- GAO recommends that the TSA update its cybersecurity roadmap and communicate changes, while the FAA should broaden its zero‑trust plan, align it with NIST guidance, and strengthen oversight of its overall cyber strategy.
- DHS agreed to modernize the TSA’s cybersecurity plan by May 2027; DOT committed to implement the FAA recommendations and provide a status update to GAO within 180 days.
- The lingering gaps come at a time when nation‑state hackers increasingly target the interconnected National Airspace System, heightening the risk of disruptive cyberattacks on U.S. aviation.
Overview of GAO Findings
The Government Accountability Office (GAO) released a report highlighting that the agencies tasked with safeguarding the United States’ aviation system—the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA)—have only partially enacted critical cybersecurity improvements. While both agencies acknowledge the growing threat from nation‑state actors seeking to destabilize American society, the audit reveals concrete shortcomings in strategy execution, policy definition, and implementation oversight that leave the National Airspace System (NAS) vulnerable to exploitation.
FAA’s 2020 Cybersecurity Strategy Goals
In 2020 the FAA unveiled a Cybersecurity Strategy centered on protecting its networks, particularly those that manage the high‑stakes task of guiding aircraft through U.S. airspace. The strategy outlined seven objectives under the network‑protection goal, ranging from threat intelligence collection to the adoption of a zero‑trust architecture. The GAO assessed progress against each objective and found a mixed record, with notable achievements in some areas but significant gaps in others that are essential for a resilient cyber posture.
Progress on Network‑Protection Objectives
The FAA has fully achieved three of the seven objectives: improving threat intelligence collection and dissemination, enhancing threat detection and mitigation capabilities, and integrating cybersecurity research into defensive operations. These accomplishments demonstrate the agency’s ability to gather and act on threat data and to leverage research outcomes. However, the remaining four objectives—critical for a holistic defense—remain only partially addressed, indicating that the FAA’s cybersecurity program is still incomplete.
Specific Lagging Areas
The four unimplemented objectives are: (1) improving monitoring, detection, and response capabilities; (2) strengthening user access controls and user activity monitoring; (3) aligning security controls with the National Institute of Standards and Technology (NIST) guidelines; and (4) implementing a zero‑trust architecture. Each of these components plays a distinct role in defending against sophisticated intrusions: continuous monitoring enables rapid incident response, robust access limits reduce insider and credential‑theft risks, NIST alignment ensures adherence to proven standards, and zero‑trust limits lateral movement after a breach.
Near‑Real‑Time Monitoring Efforts and Process Gaps
The FAA informed GAO that it is “working to implement near real‑time cyber monitoring capabilities” for the 35 systems still lacking them. GAO, however, noted that the agency lacks a comprehensive process to monitor and evaluate the implementation of its cybersecurity goals. Without systematic tracking, lessons learned from past initiatives are not institutionalized, and the FAA cannot guarantee that planned improvements are executed on schedule or adjusted based on emerging threats. This deficiency undermines confidence in the agency’s ability to achieve its network‑protection objectives.
Importance of Zero‑Trust and FAA’s Incomplete Plan
Zero‑trust architecture is regarded by security experts as a vital safeguard that assumes no implicit trust inside or outside the network, thereby limiting the damage an attacker can inflict after gaining initial access. The GAO found the FAA’s zero‑trust migration plan to be incomplete: it omits details on how zero‑trust principles will be applied to the FAA’s research and development (R&D) environments and fails to align fully with all NIST zero‑trust recommendations. Consequently, the agency cannot be assured that it is managing cybersecurity risks comprehensively across its operating landscape during ongoing NAS modernization.
Missing Elements in the Zero‑Trust Strategy
Specifically, the FAA’s plan does not include a NIST‑recommended description of how the agency will identify and manage the assets requiring protection within its R&D setting. It also neglects to incorporate NIST’s guidance on monitoring the effectiveness of the zero‑trust algorithm that autonomously grants or denies access to systems. Without these components, the FAA lacks visibility into which assets are shielded and cannot verify that its access‑decision logic functions as intended, leaving potential blind spots that adversaries could exploit.
GAO’s Warning on Zero‑Trust Alignment
GAO warned that “without fully aligning its zero‑trust implementation plan with NIST’s best practices across all operating environments, FAA cannot ensure that it is effectively and comprehensively managing cybersecurity risks during [National Airspace System] modernization.” The omission of R&D coverage and effectiveness monitoring means that even if zero‑trust is deployed in certain domains, gaps persist where critical research systems remain insufficiently protected, potentially serving as entry points for attackers aiming to disrupt flight operations or compromise safety‑critical data.
TSA’s Role Confusion and Lack of Definition
While the FAA focuses on aircraft safety and airspace management, the TSA is tasked with regulating airports’ and airlines’ cybersecurity practices, encompassing network protection and incident reporting. GAO reported that the TSA still has not specified how it will fulfill these responsibilities nor identified the offices and teams responsible for achieving its cybersecurity goals. This lack of clarity has provoked concern within the aviation sector and led partners to question the TSA’s capacity to execute its cybersecurity mandate effectively.
Stakeholder Concerns and Regulatory Confusion
In interviews with 11 selected aviation stakeholders, several voiced doubts about the TSA’s resources, authority, and expertise to regulate cybersecurity adequately. Three stakeholders noted that TSA regulations issued in March 2023 created confusion because they believed the FAA remained their regulator. A 2024 law later clarified that the FAA holds exclusive authority to issue cybersecurity rules for civil aircraft, but the prior ambiguity had already eroded trust and complicated compliance efforts for airlines and airport operators.
Interconnectivity and Overlapping Responsibilities
GAO warned that the interconnectivity between the systems regulated by the TSA (airport and airline networks) and those overseen by the FAA (flight‑navigation and air‑traffic‑management systems) creates the appearance of overlapping roles and responsibilities. Until the TSA updates its Cybersecurity Roadmap to clearly delineate its aviation cybersecurity roles and responsibilities, the agency cannot fully hold relevant entities accountable or drive continuous improvement in its cybersecurity initiatives. Clear delineation is essential to avoid duplicated efforts and to ensure that security gaps are not left unaddressed at the interface between ground‑based and airborne systems.
GAO Recommendations and Agency Responses
Based on its findings, GAO urged the TSA to revise its cybersecurity plan, communicate updates to stakeholders, and clarify its responsibilities. For the FAA, GAO recommended expanding the zero‑trust migration plan to cover all operating environments, aligning it fully with NIST guidelines, and strengthening oversight of overall cyber‑strategy implementation. The Department of Homeland Security, which oversees the TSA, agreed to implement the TSA‑specific recommendation and projected that the TSA would modernize its cybersecurity plan by the end of May 2027. The Department of Transportation, which oversees the FAA, accepted the four FAA‑specific recommendations and pledged to provide a status update to GAO within 180 days.
Implications for Aviation Security Amid Nation‑State Threats
The GAO report arrives at a moment when nation‑state hackers are increasingly probing the aviation sector as a means of deterring U.S. involvement in foreign conflicts. Given the NAS’s reliance on interconnected airborne and ground‑based systems, any weakness in monitoring, access control, standards alignment, or zero‑trust deployment can be exploited to disrupt flights, compromise safety data, or undermine public confidence. While the FAA and TSA have made strides in certain areas, the outstanding gaps identified by GAO underscore the need for accelerated, coordinated action. Implementing the recommended improvements—particularly a fully vetted zero‑trust architecture, robust real‑time monitoring, and clearly defined TSA responsibilities—will be critical to safeguarding the nation’s aviation infrastructure against evolving cyber threats.

