GAO issues nine open recommendations for FAA to curb spectrum-related cyber threats
The Department of Transportation has concurred with all nine GAO recommendations, which remain open pending FAA action.

The Government Accountability Office's latest report on aviation cybersecurity delivers nine recommendations to the Federal Aviation Administration, all of which are listed as open. The Department of Transportation, responding on behalf of the FAA, has formally concurred with each recommendation.
GAO found that while the FAA has identified electromagnetic spectrum threats - including spoofing, jamming and other interference - to the National Airspace System, it has not completed risk and mitigation assessments for seven of the eight systems examined. The agency also lacks updated security documentation and a real-time monitoring capability to detect spectrum-related threats as they occur.
Collaboration with other federal agencies and non-federal aviation stakeholders is only partially aligned with leading practices. The FAA has defined roles within interagency groups but has not established policies or procedures for information sharing, reporting and coordination with partners outside those groups. GAO notes that fully implementing these practices would improve the FAA's ability to coordinate responses to cyber incidents.
The report also highlights vulnerabilities in key communication applications used by pilots and air-traffic controllers. Systems such as ACARS and CPDLC lack robust authentication, encryption and protocol safeguards, leaving them susceptible to interception, spoofing and fraudulent clearance messages that could disrupt flight operations.
In response, the FAA is tasked with developing a formal risk-assessment report, reviewing system categorization, implementing continuous spectrum-monitoring tools, establishing outcome-tracking methods for interagency groups, creating formal guidance for external information sharing, clarifying leadership succession in collaborative bodies, expanding stakeholder inclusion, and strengthening authentication and data protection for ACARS and CPDLC. All nine actions remain pending.
Further reading


