(a)
In general— Not later than 270 days after the date of the enactment of this Act, the Secretary of Transportation shall prescribe regulations requiring covered air carriers and covered manufacturers to disclose to the Federal Aviation Administration any attempted or successful cyberattack on any system on board an aircraft, whether or not the system is critical to the safe and secure operation of the aircraft, or any maintenance or ground support system for aircraft, operated by the air carrier or produced by the manufacturer, as the case may be.
(b)
Use of disclosures by the Federal Aviation Administration— The Administrator of the Federal Aviation Administration shall use the information obtained through disclosures made under subsection (a) to improve the regulations required by section 4 and to notify air carriers, aircraft manufacturers, and other Federal agencies of cybersecurity vulnerabilities in systems on board an aircraft or maintenance or ground support systems for aircraft.