The FAA Cybersecurity Strategy (updated 2022 + ongoing 2024 update) sets the FAA-wide policy framework for cybersecurity across the aviation system. The Strategy is implemented through FAA Order 1370.123A 'Information Security and Privacy Program' which establishes: (a) the FAA Chief Information Security Officer (CISO) function reporting to the FAA Administrator; (b) the FAA Information Security and Privacy Program covering all FAA information systems + facilities; (c) cybersecurity risk management aligned with NIST RMF + NIST 800-53 + NIST CSF 2.0; (d) the FAA Insider Threat Program; (e) FAA continuity of operations and crisis management for cyber events. The Strategy + Order 1370.123A together establish the FAA cybersecurity governance baseline for the FAA's own systems + indirectly through Advisory Circulars + airworthiness rulemaking for the aviation industry it regulates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.