(a)
In general— The Commercial Aviation Communications Safety and Security Leadership Group established by the memorandum of understanding between the Department of Transportation and the Federal Communications Commission entitled “Framework for DOT–FCC Coordination of Commercial Aviation Communications Safety and Security Issues” and dated January 29, 2016 (in this section known as the “Leadership Group”), shall be responsible for evaluating the cybersecurity vulnerabilities of broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers that is installed before, on, or after, or is proposed to be installed on or after, the date of the enactment of this Act.
(b)
Responsibilities— To address cybersecurity risks arising from malicious use of communications technologies on board aircraft operated by covered air carriers, the Leadership Group shall—
(1)
ensure the development of effective methods for preventing foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board such aircraft; and
(2)
require the implementation by covered air carriers, covered manufacturers, and communications service providers of all technical and operational security measures that are deemed necessary and sufficient by the Leadership Group to prevent cyberattacks described in paragraph (1).
(c)
Report required— Not later than one year after the date of the enactment of this Act, and annually thereafter, the Leadership Group shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Transportation and Infrastructure of the House of Representatives a report on—
(1)
the technical and operational security measures developed to prevent foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers; and
(2)
the steps taken by covered air carriers, covered manufacturers, and communications service providers to implement the measures described in paragraph (1).