Protecting the Safety of Air Traffic Control and the Aviation System Act
A BILL
To direct the Administrator of the Federal Aviation Administration to issue regulations, policy, and guidance to ensure the safety of the aviation system, and for other purposes.
Sec. 2 Findings
Sec. 3 National airspace system, air traffic control, and airspace management safety
Sec. 4 Aviation product safety
“(g) Exclusive rulemaking authority—Notwithstanding any other provision of law and except as provided in section 40131, to the extent that a provision of law authorizes any Federal agency that is not the Department of Transportation, or component thereof, to issue regulations under such provision for purposes of assuring civil aircraft, aircraft engine, propeller, and appliance cybersecurity, the Administrator of the Federal Aviation Administration shall have the exclusive authority to prescribe regulations subject to such provision.”
Sec. 5 Airports
“(3) such cybersecurity standards as the Administrator may prescribe.”
Sec. 6 Federal Aviation Administration regulations, policy, and guidance
“40131. National airspace system cyber threat management process
“(a) Establishment—The Administrator of the Federal Aviation Administration shall establish a national airspace system cyber threat management process to protect the national airspace system cyber environment, including the safety, security, and efficiency of the airspace management services provided by the Administration.
“(b) Issues To be addressed—In establishing the national airspace system cyber threat management process under subsection (a), the Administrator shall, at a minimum—
“(1) monitor the national airspace system cyber environment;
“(2) in consultation with appropriate Federal agencies, evaluate the cyber threat landscape for the national airspace system, including updating such evaluation on both annual and threat-based timelines;
“(3) conduct national airspace system cyber incident analyses;
“(4) create a cyber common operating picture for the national airspace system cyber environment;
“(5) determine whether, and if so how, to conduct active cyber defense;
“(6) coordinate national airspace system cyber incident responses with other appropriate Federal agencies;
“(7) track cyber incident detection, response, mitigation implementation, recovery, and closure;
“(8) establish a process to collect relevant national airspace system cyber incident data from internal and external stakeholders; and
“(9) any other matter the Administrator determines appropriate.
“(c) Definitions—In this section, the following definitions apply:
“(1) Active cyber defense—The term active cyber defense means the use of cyber enforcement capabilities that actively interdict the movement or processing of data to mitigate a cyber threat.
“(2) Cyber common operating picture—The term cyber common operating picture means the correlation of a detected cyber incident or cyber threat in the national airspace system and other operational anomalies to provide a holistic view of potential cause and impact.
“(3) Cyber environment—The term cyber environment means the information environment consisting of the interdependent networks of information technology infrastructures and resident data, including the internet, telecommunications networks, computer systems, and embedded processors and controllers.
“(4) Cyber incident—The term cyber incident means an action that creates noticeable degradation, disruption, or destruction to the cyber environment of—
“(A) the national airspace system;
“(B) civil aircraft information, data, networks, systems, services, operations and technology; or
“(C) aeronautical products and articles.
“(5) Cyber threat—The term cyber threat means the threat of an action that, if carried out, would constitute a cyber incident, an intentional unauthorized electronic interaction, or an electronic attack.
“(6) Electronic attack—The term electronic attack means the use of electromagnetic spectrum energy to impede operations in the cyber environment, including through techniques such as jamming or spoofing.
“(7) Intentional unauthorized electronic interaction—The term intentional unauthorized electronic interaction means an intentional and unauthorized attempt to cause a safety or other negative impact on aircraft operations by—
“(A) modifying an aeronautical database;
“(B) corrupting software; or
“(C) accessing an aircraft or aeronautical system using an internet connection or other form of electronic connection.
“(8) National airspace system cyber environment—The term national airspace system cyber environment means the networking and computing technology infrastructures and data used to perform air navigation services (including air traffic control and air traffic management services), including the internet, telecommunications networks, computer systems, and embedded processors and controllers.”