Audit reveals gaps and strategic deficiencies in U.S. aviation cybersecurity oversight
The U.S. Government Accountability Office (GAO) released an audit report indicating major flaws in the cybersecurity protection of the U.S. aviation system: the FAA has only partially implemented cybersecurity strategic goals, and the TSA has failed to clearly define its cybersecurity responsibilities. The report recommends that relevant agencies accelerate corrective actions and sets a specific timeline.

According to the latest audit results, the agency responsible for protecting the U.S. aviation system from devastating cyberattacks has only partially implemented a series of important security improvements and process adjustments.
The Government Accountability Office (GAO) said in a report released Thursday that the Federal Aviation Administration (FAA) has failed to fully modernize its network monitoring and identity management capabilities, while the Transportation Security Administration (TSA) has not yet clarified its cybersecurity responsibilities and how it will implement them.
The report's findings highlight long-standing weaknesses in the U.S. aviation security system. At a time when nation-state hackers are increasingly seeking to deter U.S. involvement in overseas conflicts by undermining the stability of American society.
"Commercial flight operations rely on interconnected systems aboard aircraft and in the ground-based national airspace system," the GAO said in the report. "Given this interconnectivity, these systems are inherently more susceptible to exploitation and face a higher risk of attack by malicious actors."
FAA's cybersecurity strategy advances unevenly
The cybersecurity strategy developed by the FAA in 2020 set multiple goals for the agency, one of the most important being to protect agency networks, including high-risk critical systems responsible for guiding aircraft safely through U.S. airspace.
However, the FAA has fully achieved only three of the seven items under this network protection goal: improving threat intelligence collection and dissemination; enhancing threat detection and mitigation capabilities; and incorporating cybersecurity research into defense efforts.
In the remaining four key areas, the agency has lagged behind: improving its monitoring, detection, and response capabilities; improving user access control and user activity monitoring; aligning security controls with National Institute of Standards and Technology (NIST) guidelines; and implementing a zero trust architecture.
The FAA said it "is working to achieve near real-time network monitoring capabilities for 35 systems that do not yet have such capabilities."
The GAO noted that the FAA failed to accomplish more goals because it "lacks a comprehensive process to monitor and evaluate the implementation of its goals." Analysts wrote: "Taking steps to ensure monitoring is carried out as planned, including incorporating lessons learned, will help the agency achieve its goals of protecting its networks and systems and effectively mitigate cybersecurity risks."
Zero trust implementation hindered
Security experts consider zero trust architecture a key tool for limiting the damage hackers can cause after breaching a network, but according to the GAO, the FAA's zero trust migration plan is incomplete. Auditors found that the plan omitted details on applying zero trust to the FAA's research and development systems and failed to fully align with NIST's zero trust recommendations.
The GAO noted that the FAA's plan did not include NIST's recommended description of how to identify and manage assets in its research and development environment that need protection. Additionally, the plan did not incorporate NIST's recommendations on monitoring the effectiveness of zero trust algorithms, which would autonomously grant or deny access to certain computer systems.
"If it fails to fully align its zero trust implementation plan with NIST best practices across all operational environments, the FAA cannot ensure it effectively and comprehensively manages cybersecurity risks during the modernization of the national airspace system," the GAO said.
TSA's responsibilities are unclear
The FAA is responsible for certifying the overall safety of aircraft and guiding their flights, while the TSA oversees cybersecurity practices at airports and airlines, covering everything from network protection to incident reporting. But according to the GAO, the TSA has still not clarified how it will carry out these responsibilities, nor has it identified the offices and teams responsible for achieving its cybersecurity goals.
This inaction has raised concerns within the aviation industry and has led TSA partners to doubt its ability to fulfill its cybersecurity mission.
"In interviews with 11 selected aviation stakeholders, some expressed concerns about the clarity of TSA's role and responsibilities in aviation cybersecurity," the GAO said in the report. One airline told auditors they believed the TSA "lacks sufficient resources, authority, and expertise to properly regulate cybersecurity," while three other stakeholders said regulations issued by the TSA in March 2023 caused confusion because they believed the FAA was their regulator. (A 2024 law clarified that the FAA has exclusive authority to issue cybersecurity rules for civil aircraft.)
The GAO warned that the interconnectivity between systems regulated by the TSA and those regulated by the FAA "creates the appearance of overlapping roles and responsibilities between the two agencies." "Until the TSA updates its cybersecurity roadmap to clarify its aviation cybersecurity roles and responsibilities, the agency cannot fully hold relevant entities accountable or continuously improve its related efforts."
Recommendations and responses
Based on its findings, the GAO urged the TSA to update its cybersecurity plan and communicate these updates with stakeholders. Auditors also asked the FAA to make its zero trust migration plan more comprehensive, align it with NIST recommendations, and improve oversight of the implementation of its overall cyber strategy.
The Department of Homeland Security, which oversees the TSA, agreed to implement the GAO's recommendations for the TSA and said it expects the TSA to complete the modernization of its cybersecurity plan by the end of May 2027. The Department of Transportation, which oversees the FAA, agreed to implement the four recommendations in the report for the FAA and committed to providing progress updates to the GAO within 180 days.