
Despite efforts to close security vulnerabilities, gaps remain in critical air traffic control systems, the Transportation Department Office of Inspector General (DOT OIG) found in newly-released audit results. According to the DOT OIG, the FAA had not fully implemented 1,836, or 11.3%, of the 16,245 required security controls for the 45 automation, surveillance/flight services, communications, and navigation/weather systems that the agency had categorized as “high impact.”
“Because the FAA has not ensured that all required high baseline security controls have been selected, properly implemented, documented, and tracked, or that risks have been otherwise mitigated where controls cannot be implemented, many of the FAA’s high-impact systems remain vulnerable to cyberattacks,” the DOT OIG maintained. “Consequently, the FAA cannot have assurance that critical NAS systems are protected from cybersecurity threats that could severely disrupt air traffic operations.”