Avionics News June 2017 - 34

CYBERSECURITY IN THE SKY
Continued from page 33

anyone to exert control over aircraft systems as a crew
member is required to accept, acknowledge and act upon
CPDLC messages," Zban said.
The second category of cockpit connectivity comes
through portable electronic devices. More and more
pilots use portable electronic devices as electronic flight
bags, typically using a common device - the iPad. The
iPad and some other portable equipment are Class 1
EFBs. Use of these EFBs by Part 121, 125, 135, and 91
subpart F and subpart K operators must be authorized
by the FAA, and their use is limited by AC 120-76A.
However, the AC provides good guidance for all aircraft
operators and pilots regarding general security measures.
It's always good to assume the worst in any safetycritical environment, so cabin devices must be, and
are, segregated and protected from standard cabin
connections. Certificated, installed hardware includes
built-in protections, but portable electronic devices
are vulnerable to attacks in the cabin system. An
Ethernet router can be used to create a firewall between
connectivity and the cockpit. Portable electronic devices
used in the cockpit also should have current, reputable
anti-virus/anti-malware software installed.
Train to mitigate cabin and
cockpit vulnerabilities
Wolfe and Zban recommend training to mitigate
cybersecurity vulnerabilities in the cabin and the cockpit.
Both pilots in the cockpit and passengers in the cabin can
benefit from cybersecurity training.
Flight departments and air carriers should provide
their pilots with basic cybersecurity training, including
using strong passwords, safe charging of devices, and
properly logging out of devices. Pilots should be trained
to verify messages inconsistent with expectations and
standard operations by using voice communications.
"One of the primary reasons we have pilots in the
cockpit is to use their human brains and apply critical
thinking," Wolfe said.
Some aircraft operators - especially flight departments,
which tend to have a clear nexus with their passengers
- might consider offering passengers training or at least
ensure passengers are aware of and comply with the
company's security policies when on the company aircraft.
34

avionics news

*

june

2017

Passenger training should include the same best
practices as those for pilots: basic cybersecurity
awareness and strong password development, plus use of
VPNs or other secure network access.
The increased vulnerability of the cabin system makes
passenger awareness and training even more important.
Regulatory climate
The FAA and the International Civil Aviation
Organization are looking closely at cybersecurity. An
Aviation Rulemaking Advisory Council on Aircraft
Systems Information Security/Protection recently
presented the FAA with 30 recommendations for
improving cybersecurity in the national airspace system.
The goal of the ARAC ASISP working group was to
consider regulation, policy, and/or guidance to identify
aircraft vulnerabilities and mitigate risks in a harmonized
manner with other aviation authorities and regulators.
It remains to be seen what will come of the 30
recommendations, many of which relate to certification
or design, but some include agency or industry best
practices in operations.
The ICAO also has taken on cybersecurity concerns
through the AvSec panel, a group of industry and
government security experts. The ICAO is focused on
information sharing and coordination across civil aviation
safety and security to address aviation cybersecurity on a
global level. In addition, the ICAO Annex 17, Chapter 4
outlines preventive security measures.
For now, certificated, installed cockpit hardware in
U.S.-registered aircraft is standardized through special
conditions issued by the FAA, and portable electronic
devices are standardized for commercial air carriers
through the EFB authorization process. But cabin
connectivity systems and portable electronic devices
for Part 91 operators require industry-driven, voluntary
compliance with best practices. Additional regulation,
standards, and/or best practices are likely to be issued
by national aviation authorities and the ICAO during
the next several years to address the ever-changing
environment of cyberrisks.
To keep your data secure, whether as a passenger
in the cabin or pilot in the cockpit, in most cases, the
basics of cybersecurity are most crucial: Be aware of the
risk, use strong passwords, consider use of a VPN for
passengers, and use effective anti-virus/anti-malware
software on all devices.q



Table of Contents for the Digital Edition of Avionics News June 2017

No label
Avionics News June 2017 - Intro
Avionics News June 2017 - No label
Avionics News June 2017 - Cover2
Avionics News June 2017 - 1
Avionics News June 2017 - 2
Avionics News June 2017 - 3
Avionics News June 2017 - 4
Avionics News June 2017 - 5
Avionics News June 2017 - 6
Avionics News June 2017 - 7
Avionics News June 2017 - 8
Avionics News June 2017 - 9
Avionics News June 2017 - 10
Avionics News June 2017 - 11
Avionics News June 2017 - 12
Avionics News June 2017 - 13
Avionics News June 2017 - 14
Avionics News June 2017 - 15
Avionics News June 2017 - 16
Avionics News June 2017 - 17
Avionics News June 2017 - 18
Avionics News June 2017 - 19
Avionics News June 2017 - 20
Avionics News June 2017 - 21
Avionics News June 2017 - 22
Avionics News June 2017 - 23
Avionics News June 2017 - 24
Avionics News June 2017 - 25
Avionics News June 2017 - 26
Avionics News June 2017 - 27
Avionics News June 2017 - 28
Avionics News June 2017 - 29
Avionics News June 2017 - 30
Avionics News June 2017 - 31
Avionics News June 2017 - 32
Avionics News June 2017 - 33
Avionics News June 2017 - 34
Avionics News June 2017 - 35
Avionics News June 2017 - 36
Avionics News June 2017 - 37
Avionics News June 2017 - 38
Avionics News June 2017 - 39
Avionics News June 2017 - 40
Avionics News June 2017 - 41
Avionics News June 2017 - 42
Avionics News June 2017 - 43
Avionics News June 2017 - 44
Avionics News June 2017 - 45
Avionics News June 2017 - 46
Avionics News June 2017 - 47
Avionics News June 2017 - 48
Avionics News June 2017 - 49
Avionics News June 2017 - 50
Avionics News June 2017 - 51
Avionics News June 2017 - 52
Avionics News June 2017 - 53
Avionics News June 2017 - 54
Avionics News June 2017 - 55
Avionics News June 2017 - 56
Avionics News June 2017 - 57
Avionics News June 2017 - 58
Avionics News June 2017 - 59
Avionics News June 2017 - 60
Avionics News June 2017 - 61
Avionics News June 2017 - 62
Avionics News June 2017 - 63
Avionics News June 2017 - 64
Avionics News June 2017 - 65
Avionics News June 2017 - 66
Avionics News June 2017 - 67
Avionics News June 2017 - 68
Avionics News June 2017 - 69
Avionics News June 2017 - 70
Avionics News June 2017 - 71
Avionics News June 2017 - 72
Avionics News June 2017 - 73
Avionics News June 2017 - 74
Avionics News June 2017 - 75
Avionics News June 2017 - 76
Avionics News June 2017 - 77
Avionics News June 2017 - 78
Avionics News June 2017 - 79
Avionics News June 2017 - 80
Avionics News June 2017 - 81
Avionics News June 2017 - 82
Avionics News June 2017 - 83
Avionics News June 2017 - 84
Avionics News June 2017 - 85
Avionics News June 2017 - 86
Avionics News June 2017 - 87
Avionics News June 2017 - 88
Avionics News June 2017 - Cover3
Avionics News June 2017 - Cover4
https://www.nxtbook.com/allen/avne/60-10
https://www.nxtbook.com/allen/avne/60-9
https://www.nxtbook.com/allen/avne/60-8
https://www.nxtbook.com/allen/avne/60-7
https://www.nxtbook.com/allen/avne/60-6
https://www.nxtbook.com/allen/avne/60-5
https://www.nxtbook.com/allen/avne/60-4
https://www.nxtbook.com/allen/avne/60-3
https://www.nxtbook.com/allen/avne/60-2
https://www.nxtbook.com/allen/avne/60-1
https://www.nxtbook.com/allen/avne/59-12
https://www.nxtbook.com/allen/avne/59-11
https://www.nxtbook.com/allen/avne/59-10
https://www.nxtbook.com/allen/avne/59-9
https://www.nxtbook.com/allen/avne/59-8
https://www.nxtbook.com/allen/avne/59-7
https://www.nxtbook.com/allen/avne/59-6
https://www.nxtbook.com/allen/avne/59-5
https://www.nxtbook.com/allen/avne/59-4
https://www.nxtbook.com/allen/avne/59-3
https://www.nxtbook.com/allen/avne/59-2
https://www.nxtbook.com/allen/avne/59-1
http://www.brightcopy.net/allen/avne/58-12
http://www.brightcopy.net/allen/avne/58-11
http://www.brightcopy.net/allen/avne/58-10
http://www.brightcopy.net/allen/avne/58-9
http://www.brightcopy.net/allen/avne/58-8
http://www.brightcopy.net/allen/avne/58-7
http://www.brightcopy.net/allen/avne/58-6
http://www.brightcopy.net/allen/avne/58-5
http://www.brightcopy.net/allen/avne/58-4
http://www.brightcopy.net/allen/avne/58-3
http://www.brightcopy.net/allen/avne/58-2
http://www.brightcopy.net/allen/avne/58-1
http://www.brightcopy.net/allen/avne/57-12
http://www.brightcopy.net/allen/avne/57-11
http://www.brightcopy.net/allen/avne/57-10
http://www.brightcopy.net/allen/avne/57-9
http://www.brightcopy.net/allen/avne/57-8
http://www.brightcopy.net/allen/avne/57-7
http://www.brightcopy.net/allen/avne/57-6
http://www.brightcopy.net/allen/avne/57-5
http://www.brightcopy.net/allen/avne/57-4
http://www.brightcopy.net/allen/avne/57-3
http://www.brightcopy.net/allen/avne/57-2
http://www.brightcopy.net/allen/avne/57-1
http://www.brightcopy.net/allen/avne/56-12
http://www.brightcopy.net/allen/avne/56-11
http://www.brightcopy.net/allen/avne/56-10
http://www.brightcopy.net/allen/avne/56-9
http://www.brightcopy.net/allen/avne/56-8
http://www.brightcopy.net/allen/avne/56-7
http://www.brightcopy.net/allen/avne/56-6
http://www.brightcopy.net/allen/avne/56-5
http://www.brightcopy.net/allen/avne/56-4
http://www.brightcopy.net/allen/avne/56-3
http://www.brightcopy.net/allen/avne/56-2
http://www.brightcopy.net/allen/avne/56-1
http://www.brightcopy.net/allen/avne/55-12
http://www.brightcopy.net/allen/avne/55-11
http://www.brightcopy.net/allen/avne/55-10
http://www.brightcopy.net/allen/avne/55-9
http://www.brightcopy.net/allen/avne/55-8
http://www.brightcopy.net/allen/avne/55-7
http://www.brightcopy.net/allen/avne/55-6
http://www.brightcopy.net/allen/avne/55-5
http://www.brightcopy.net/allen/avne/55-4
http://www.brightcopy.net/allen/avne/55-3
http://www.brightcopy.net/allen/avne/55-02
http://www.brightcopy.net/allen/avne/55-01
http://www.brightcopy.net/allen/avne/54-12
http://www.brightcopy.net/allen/avne/54-11
http://www.brightcopy.net/allen/avne/54-10
http://www.brightcopy.net/allen/avne/54-9
http://www.brightcopy.net/allen/avne/54-8
http://www.brightcopy.net/allen/avne/54-7
http://www.brightcopy.net/allen/avne/54-6
http://www.brightcopy.net/allen/avne/54-5
http://www.brightcopy.net/allen/avne/54-4
http://www.brightcopy.net/allen/avne/54-3
http://www.brightcopy.net/allen/avne/54-2
http://www.brightcopy.net/allen/avne/54-1
http://www.brightcopy.net/allen/avne/53-12
http://www.brightcopy.net/allen/avne/53-11
http://www.brightcopy.net/allen/avne/53-10
http://www.brightcopy.net/allen/avne/53-9
http://www.brightcopy.net/allen/avne/53-8
http://www.brightcopy.net/allen/avne/53-7
http://www.brightcopy.net/allen/avne/53-6
http://www.brightcopy.net/allen/avne/53-5
http://www.brightcopy.net/allen/avne/53-4
http://www.brightcopy.net/allen/avne/53-3
http://www.brightcopy.net/allen/avne/53-2
http://www.brightcopy.net/allen/avne/53-1
http://www.brightcopy.net/allen/avne/52-12
http://www.brightcopy.net/allen/avne/52-11
http://www.brightcopy.net/allen/avne/52-10
http://www.brightcopy.net/allen/avne/52-9
http://www.brightcopy.net/allen/avne/52-8
https://www.nxtbook.com/allen/avne/52-7
https://www.nxtbook.com/allen/avne/52-6
https://www.nxtbook.com/allen/avne/52-5
https://www.nxtbook.com/allen/avne/52-4
https://www.nxtbook.com/allen/avne/52-3
https://www.nxtbook.com/allen/avne/52-2
https://www.nxtbook.com/allen/avne/52-1
https://www.nxtbook.com/allen/avne/51-12
https://www.nxtbook.com/allen/avne/51-11
https://www.nxtbook.com/allen/avne/51-10
https://www.nxtbook.com/allen/avne/51-9
https://www.nxtbook.com/allen/avne/51-8
https://www.nxtbook.com/allen/avne/51-7
https://www.nxtbook.com/allen/avne/51-6
https://www.nxtbook.com/allen/avne/51-5
https://www.nxtbook.com/allen/avne/51-4
https://www.nxtbook.com/allen/avne/51-3
https://www.nxtbook.com/allen/avne/51-2
https://www.nxtbook.com/allen/avne/51-1
https://www.nxtbook.com/allen/avne/50-12
https://www.nxtbook.com/allen/avne/50-11
https://www.nxtbook.com/allen/avne/50-10
https://www.nxtbook.com/allen/avne/50-9
https://www.nxtbook.com/allen/avne/50-8
https://www.nxtbook.com/allen/avne/50-7
https://www.nxtbook.com/allen/avne/50-6
https://www.nxtbook.com/allen/avne/50-5
https://www.nxtbook.com/allen/avne/50-4
https://www.nxtbook.com/allen/avne/50-3
https://www.nxtbook.com/allen/avne/50-2
https://www.nxtbook.com/allen/avne/50-1
https://www.nxtbook.com/allen/avne/49-12
https://www.nxtbook.com/allen/avne/49-11
https://www.nxtbook.com/allen/avne/49-10
https://www.nxtbook.com/allen/avne/49-9
https://www.nxtbook.com/allen/avne/49-8
https://www.nxtbook.com/allen/avne/49-7
https://www.nxtbook.com/allen/avne/49-6
https://www.nxtbook.com/allen/avne/49-5
https://www.nxtbook.com/allen/avne/49-4
https://www.nxtbook.com/allen/avne/49-3
https://www.nxtbook.com/allen/avne/49-2
https://www.nxtbook.com/allen/avne/49-1
https://www.nxtbook.com/allen/avne/48-12
https://www.nxtbook.com/allen/avne/48-11
https://www.nxtbookmedia.com