Vulnerability management + software assurance for aviation systems covers: (a) RTCA DO-178C 'Software Considerations in Airborne Systems' (the airworthiness software-assurance baseline - needs_licensed_copy); (b) DO-326A + DO-356A airworthiness security methods integrated with DO-178C; (c) Coordinated Vulnerability Disclosure (CVD) for aircraft + ATM + airport systems through the FAA Aviation CVD process + the joint A-ISAC CVD framework; (d) software bill of materials (SBOM) for aviation software per Executive Order 14028 + the NTIA SBOM minimum elements + RTCA DO-356A appendices; (e) third-party software-supplier vulnerability response SLAs; (f) coordination with CISA Known Exploited Vulnerabilities (KEV) catalog + sectoral threat-intelligence feeds. Aviation vulnerability management is constrained by the long airworthiness-certification cycle - a software patch may require months of certification before it can be applied to a flying aircraft.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.