FAA Advisory Circular 25-21 establishes the cybersecurity architecture framework for transport-category aircraft (14 CFR Part 25) covering: (a) aircraft information system domain (AISD) architecture - the cabin systems + IFE + airline operations systems isolated from the safety-critical flight controls + avionics; (b) network security between aircraft domains (avionics + AISD + passenger information services PESD - the THREE-DOMAIN ARINC 811 architecture); (c) external network connectivity including SATCOM + Wi-Fi + cellular + 5G ground stations; (d) cybersecurity-related airworthiness requirements traceable to 14 CFR Part 25 Special Conditions on cybersecurity. AC 25-21 is the operational counterpart to RTCA DO-326A / ED-202A airworthiness security process specification. Aircraft manufacturers (Boeing + Airbus + Embraer + Bombardier + Gulfstream + Cessna + others) apply DO-326A + AC 25-21 in their airworthiness submissions for cybersecurity-affected aircraft modifications + new type certifications.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.