FAA Cybersecurity Framework for Aviation
The Federal Aviation Administration (FAA) cybersecurity framework addresses cybersecurity risks in civil aviation systems including air traffic management, aircraft systems, and airport infrastructure. FAA Order 1370.82A establishes the agency's cybersecurity programme aligned with NIST CSF. The framework covers airborne systems (DO-326A/ED-202A), ground systems, and organisational security. The Aviation Cybersecurity Strategy (2023) outlines the FAA's approach to evolving cyber threats including connected aircraft and remotely piloted systems.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Cybersecurity Governance
National cybersecurity policy framework
| Code | Title |
|---|---|
| FAA-CS-1.1 | Governance Structure |
| FAA-CS-1.2 | Policies and Procedures |
| FAA-CS-1.3 | Roles and Responsibilities |
| JP-FSA-CYB-GOV-01 | Board and Senior Management Oversight |
| JP-FSA-CYB-GOV-02 | Cybersecurity Risk Assessment |
| JP-FSA-CYB-GOV-03 | Third-Party Risk Management |
| KUWAIT-GOV-01 | Cybersecurity Strategy and Policy |
| KUWAIT-GOV-02 | Organizational Structure and Accountability |
| KUWAIT-GOV-03 | Risk Management Framework |
| KUWAIT-GOV-04 | Third-Party Security Management |
| PNG-CC-CG-01 | National Cybersecurity Framework |
| PNG-CC-CG-02 | NICTA Oversight |
| PNG-CC-CG-03 | Incident Response |
| RBI-CYB-GOV-01 | Board-Approved Cyber Security Policy |
| RBI-CYB-GOV-02 | CISO and Security Organization |
| RBI-CYB-GOV-03 | Cyber Crisis Management Plan |
Detection, Response and Recovery
| Code | Title |
|---|---|
| FAA-CS-4.1 | Cyber Threat Detection |
| FAA-CS-4.2 | Incident Response |
| FAA-CS-4.3 | Recovery Capabilities |
Protection and Defense
Preventive security controls and protective measures
| Code | Title |
|---|---|
| FAA-CS-2.1 | Network and System Protection |
| FAA-CS-2.2 | Aircraft System Security |
| FAA-CS-2.3 | Air Traffic Control Security |
| OMAN-PRO-01 | Identity and Access Management |
| OMAN-PRO-02 | Data Protection |
| OMAN-PRO-03 | Network and Endpoint Security |
| OMAN-PRO-04 | Security Awareness and Training |
Risk Management
Establishing and maintaining a cyber security risk management program
| Code | Title |
|---|---|
| AASB-S2-25a | Risk Identification and Assessment Processes |
| AASB-S2-25b | Opportunity Identification Processes |
| AASB-S2-25c | Integration with Overall Risk Management |
| AESCSF-RM-1 | Cyber Security Risk Management Strategy |
| AESCSF-RM-2 | Risk Assessment Process |
| AESCSF-RM-3 | Risk Response and Mitigation |
| AESCSF-RM-4 | Risk Management Integration |
| CDP-RM-1 | Risk Identification Process |
| CDP-RM-2 | Dependencies and Impacts Assessment |
| CDP-RM-3 | Value Chain Risk Assessment |
| FAA-CS-3.1 | Data-Driven Risk Management |
| FAA-CS-3.2 | Supply Chain Risk Management |
| FAA-CS-3.3 | Vulnerability Assessment |
| GAMP5-1.1 | Risk-Based Approach |
| GAMP5-1.2 | Patient Safety Risk Assessment |
| GAMP5-1.3 | Functional Risk Assessment |
Workforce and Collaboration
| Code | Title |
|---|---|
| FAA-CS-5.1 | Cybersecurity Workforce Development |
| FAA-CS-5.2 | Inter-Agency Collaboration |
| FAA-CS-5.3 | Industry Engagement |
Maps to 642 other frameworks
Frequently Asked Questions
What is FAA Cybersecurity Framework for Aviation?
FAA Cybersecurity Framework for Aviation is a compliance framework from United States (FAA) with 5 domains and 45 controls. The Federal Aviation Administration (FAA) cybersecurity framework addresses cybersecurity risks in civil aviation systems including air traffic management, aircraft systems, and airport infrastructure. FAA Order 1370.82A establishes the agency's cybersecurity programme aligned with NIST CSF. The framework covers airborne systems (DO-326A/ED-202A), ground systems, and organisational security. The Aviation Cybersecurity Strategy (2023) outlines the FAA's approach to evolving cyber threats including connected aircraft and remotely piloted systems. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FAA Cybersecurity Framework for Aviation have?
FAA Cybersecurity Framework for Aviation has 45 controls organised across 5 domains. The largest domains are Cybersecurity Governance (16 controls), Risk Management (16 controls), Protection and Defense (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FAA Cybersecurity Framework for Aviation map to?
FAA Cybersecurity Framework for Aviation maps to 642 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (47% coverage), Protective Security Policy Framework (PSPF) Release 2024 (47% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (47% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with FAA Cybersecurity Framework for Aviation compliance?
Start your FAA Cybersecurity Framework for Aviation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FAA Cybersecurity Framework for Aviation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required