TSA issues aviation regulations for airlines, airports facing 'persistent cybersecurity threat'
Full article635 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The agency's new cybersecurity rules issued on Tuesday followed the Biden administration's national cybersecurity strategy.
In the latest move from the Biden administration to strengthen cybersecurity protections for critical infrastructure operators, the Transportation Security Administration on Tuesday announced regulations to compel airports along with aircraft owners and operators to improve their digital defenses in the face of growing threats.
“Protecting our nation’s transportation system is our highest priority and TSA will continue to work closely with industry stakeholders across all transportation modes to reduce cybersecurity risks and improve cyber resilience to support safe, secure and efficient travel,” TSA Administrator David Pekoske said in a statement. “This amendment to the aviation security programs extends similar performance-based requirements that currently apply to other transportation system critical infrastructure.”
The announcement comes just days after the Biden administration released the National Cybersecurity Strategy that calls for more stringent regulations for critical infrastructure. TSA’s announcement also follows a move from the Environmental Protection Agency to introduce new rules for the water sector. TSA issued similar measures for the passenger and freight railroad carriers in October, and the National Regulatory Commission issued updated guidance as well for the first time in years.
TSA said it is taking “emergency action because of persistent cybersecurity threats against U.S. critical infrastructure, including the aviation sector.” Pekoske said last year that the transportation agency was working on new rules for the industry. Additionally, White House officials have previously held classified cybersecurity briefings with airline executives in September.
Aviation owners and operators that fall under TSA’s authority are already required to report cybersecurity breaches to the U.S. Cybersecurity and Infrastructure Security Agency, have an established cybersecurity point of contact, develop an incident response plan and complete a vulnerability assessment, according to the press release.
Airlines must now develop a TSA-approved implementation plan that describes the measures companies are taking to improve digital defenses. The plans require that aviation sector operators can safely operate if operational technology or IT networks are compromised, create measures to prevent unauthorized access to critical systems, implement continuous monitoring and detection policies and keep up with patching using risk-based methods.
While this latest rule does not appear to draw the ire of the aviation industry, according to the Washington Post, previous rulemaking from TSA for the pipeline industry drew such a harsh response from industry and experts the agency released updated security directive. TSA is also working on a more permanent rulemaking process for the pipeline industry to replace the security directives issued shortly after the Colonial Pipeline ransomware attack.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/tsa-cybersecurity-airlines/