• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Aerospace Cybersecurity
September 23 2020 9:21 am

EASA, FAA Officials Talk Cybersecurity Policy Updates for Connected Aircraft Systems

K

Kelsey Reichmann

cybersecurity

Regulatory officials from the European Union Aviation Safety Agency (EASA) and the Federal Aviation Administration (FAA) discussed some of their latest cybersecurity policy initiatives and upcoming regulatory updates during the first day of the Global Connected Aircraft Summit's second "Cabin Chats" web series.

During the first day of the Global Connected Aircraft Summit's second "Cabin Chats" web series, cybersecurity experts from the European Union Aviation Safety Agency (EASA) and the Federal Aviation Administration (FAA) came together to discuss risk management and upcoming policy changes for stakeholders across the connected aircraft ecosystem.

Peter Skaves, Advanced Avionics Chief Scientific and Technical Advisor (CSTA) at FAA, said the biggest threat from the standpoint of the FAA is access points via public networks. The FAA's assessment is that the cybersecurity risks for the e-enabled architecture and infrastructure of the aircraft cannot physically be hacked while flying.

Slide pulled from a presentation by Peter Skaves, Advanced Avionics CSTA at FAA, during the Global Connected Aircraft Summit.

"Every part in the airplane, every software part, has a unique electronic identifier and the only time we can load up these software parts is on a maintenance action when the planes are parked at the gate," Skaves said. "Once the maintenance action is done, the hardware interlocks are not available for any additional software updates. There is no room for you to come over here and go rogue on these displays or anywhere in the airplane. There is no physical way you can do that."

In recent years, professional hackers from firms such as IOACTIVE have demonstrated their ability to hack into a commercial airplane's satellite internet modem, although the only such hacking that has been demonstrated impacted passenger mobile devices connected to the in-flight Internet with no ability to affect safety critical avionics systems. During the web-based version of Black Hat 2020 last month, Oxford PhD candidate and cybersecurity researcher James Pavur, demonstrated how his team was able to use about $300 in home television equipment and specialized software to enable "satellite eavesdropping" on in-flight passenger Internet data.

Slide pulled from a presentation by Peter Skaves, Advanced Avionics CSTA at FAA, at the Global Connected Aircraft Summit.

The FAA and EASA are continuing to expand industry guidance, education and regulations to prevent cybersecurity risks in the air and on the ground. 

Cyrille Rosay, a senior cybersecurity expert at EASA, explained how the agency has amended its cybersecurity requirements for commercial aircraft, helicopters, and jet engines. The amendments were originally proposed  in 2019. EASA's "Decision 2020/006/R," published in July, issues amendments for product certification and continued airworthiness to already existing certification specifications (CS) and acceptable means of compliance (AMC). These regulations do not yet apply to unmanned aircraft.

Decision 2020/006/R aims to protect aircraft against threats to on-board electronic networks and systems. The amendments in this decision affect everything from general requirements on systems and equipment function in AMC 23.2510 to APU Control Systems and information security protection in CS-APU 90. The new amendments are to become effective in January 2021, according to information presented by Rosay.

Skaves said that the FAA plans to publish an advisory circular to recognize standards for Transport Category Airplanes. The advisory circular will be combined with RTCA industry-accepted standards. 

A slide in Skaves presentation noted, "The FAA plans to publish an advisory circular as one means but not the only means to recognize these [Aircraft Systems Information Security/Protection] ASISP industry standards for Transport Category Airplanes."

Juan Anton, cybersecurity in aviation & emerging risks section manager at EASA, discussed how the agency is also working on managing cybersecurity risks by organizations. Anton explained how EASA regulatory framework is focused on preventing accidents, where managing cybersecurity risks focuses on safety risks that result from intentional acts.

"Our rules have always been focused on safety…We put safety layers to stop something from happening, but we assume that it happens just by chance when all things align. We never thought about somebody trying to exploit those vulnerabilities or flaws," Anton said.

Anton said the solution would be an Information Security Management System (ISMS) and reporting of information security incidents that may impact aviation safety. The ISMS would identify areas that would be vulnerable to cyber risks, identify cyber risks resulting from its interfaces with other organizations, perform information security risk assessments, and ensure personnel has the skills to perform their tasks.

EASA is currently working on an ISMS and predicts it will be adopted by the European Commission in 2022. 

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles