ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

49 U.S.C. § 40131National airspace system cyber threat management process

submitted 2 years ago by Pub. L. 118-63 to r/title-49-TRANSPORTATION · 437 words · no verdicts yet

in plain englishAI-generated · not legal advice

The FAA must build a process to manage cyber threats to the airspace system. It must track incidents, share threat data, and work with other federal agencies. The section defines key terms like "cyber incident" and "significant cyber incident."

(a) Establishment. The FAA Administrator, working with other agency heads as needed, must set up a process to manage cyber threats to the national airspace system's computer environment, protecting the safety, security, and efficiency of air navigation services. (b) Issues To Be Addressed. In building this process, the Administrator must at least: (1) watch the airspace system for major cybersecurity incidents; (2) work with other federal agencies to judge the cyber threat landscape, updating this yearly and whenever new threats appear; (3) analyze national airspace cyber incidents; (4) build a "cyber common operating picture" of the airspace system's cyber environment; (5) coordinate responses to major cyber incidents with other federal agencies; (6) track how incidents are found, handled, fixed, recovered from, and closed; (7) set up or use an existing way to share data about major cyber incidents; (8) help report major cybersecurity incidents, including through the Cybersecurity and Infrastructure Security Agency; and (9) consider any other matter the Administrator thinks is relevant. (c) Definitions. (1) "Cyber common operating picture" means linking a detected cyber incident or threat in the airspace system with other unusual events, to give a full picture of its likely cause and impact. (2) "Cyber environment" means the information systems that make up the digital world — networks, the internet, phone systems, computers, and embedded processors and controllers. (3) "Cyber incident" means an action that noticeably degrades, disrupts, or destroys the cyber environment and causes a safety or other harm to (A) the national airspace system, (B) civil aircraft, or (C) aviation products and parts. (4) "Cyber threat" means the threat that, if carried out, would become a cyber incident or an electronic attack. (5) "Electronic attack" means using electromagnetic energy to disrupt the cyber environment, such as jamming or spoofing. (6) "Significant cyber incident" means a cyber incident, or a group of related ones, that the Administrator believes will likely cause real harm to the U.S. national airspace system.
the actual law source: uscode.house.gov ↗public domain
(a)Establishment.—

The Administrator of the Federal Aviation Administration, in consultation with the heads of other agencies as the Administrator determines necessary, shall establish a national airspace system cyber threat management process to protect the national airspace system cyber environment, including the safety, security, and efficiency of air navigation services provided by the Administration.

(b)Issues To Be Addressed.—

In establishing the national airspace system cyber threat management process under subsection (a), the Administrator shall, at a minimum—

(1)

monitor the national airspace system for significant cybersecurity incidents;

(2)

in consultation with appropriate Federal agencies, evaluate the cyber threat landscape for the national airspace system, including updating such evaluation on both annual and threat-based timelines;

(3)

conduct national airspace system cyber incident analyses;

(4)

create a cyber common operating picture for the national airspace system cyber environment;

(5)

coordinate national airspace system significant cyber incident responses with other appropriate Federal agencies;

(6)

track significant cyber incident detection, response, mitigation implementation, recovery, and closure;

(7)

establish a process, or utilize existing processes, to share relevant significant cyber incident data related to the national airspace system;

(8)

facilitate significant cybersecurity reporting, including through the Cybersecurity and Infrastructure Agency; and

(9)

consider any other matter the Administrator determines appropriate.

(c)Definitions.—

In this section:

(1)Cyber common operating picture.—

The term “cyber common operating picture” means the correlation of a detected cyber incident or cyber threat in the national airspace system and other operational anomalies to provide a holistic view of potential cause and impact.

(2)Cyber environment.—

The term “cyber environment” means the information environment consisting of the interdependent networks of information technology infrastructures and resident data, including the internet, telecommunications networks, computer systems, and embedded processors and controllers.

(3)Cyber incident.—

The term “cyber incident” means an action that creates noticeable degradation, disruption, or destruction to the cyber environment and causes a safety or other negative impact on operations of—

(A)

the national airspace system;

(B)

civil aircraft; or

(C)

aeronautical products and articles.

(4)Cyber threat.—

The term “cyber threat” means the threat of an action that, if carried out, would constitute a cyber incident or an electronic attack.

(5)Electronic attack.—

The term “electronic attack” means the use of electromagnetic spectrum energy to impede operations in the cyber environment, including through techniques such as jamming or spoofing.

(6)Significant cyber incident.—

The term “significant cyber incident” means a cyber incident, or a group of related cyber incidents, that the Administrator determines is likely to result in demonstrable harm to the national airspace system of the United States.

Source credit: (Added Pub. L. 118–63, title III, § 393(a), May 16, 2024, 138 Stat. 1144.)

history & why it existsrecord from the source credit
  • 2024Enacted · Pub. L. 118-63 · 138 Stat. 1144

A history note hasn’t been published yet. The record shows enactment by Pub. L. 118-63 on 2024-05-16.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case