Terry Gerton You have dug into aviation cybersecurity. That depends on a growing network of connected systems on the ground and the aircraft across federal departments. Was there anything that prompted this particular look?
Jennifer Franks Yeah, absolutely. So what prompted this mandate was the FAA Reauthorization Act of 2024. And that act included a provision for GAO to go in and evaluate both the Federal Aviation Administration, as well as the Transportation Security Administration’s roles and responsibilities managing cybersecurity, and specifically aviation cybersecurity.
Terry Gerton The FAA and the TSA are supposed to work together here as you began the examination, what did you find both about their respective roles and how well they actually are working together?
Jennifer Franks That’s a very good question. So we found out that there are some deviances with how they are actually working and collaborating in this cybersecurity space. FAA has defined and clearly assigned roles and responsibilities for carrying out the agency’s related goals and objectives in this space. But in the contrast, TSA has not. And with the lack of really defining and clarifying your roles and responsibilities, what it is we found as we started to interview stakeholders from industry, including airlines and other industry related groups, they were confused as well with TSA’s role and responsibility and some of the guidance that was coming out. So, helping to streamline that information was something that we were talking with the stakeholders very early on that could have been helpful for them in their environment.
Terry Gerton Really interesting that you brought the industry into this conversation. If there’s confusion out there between the TSA, the FAA, and the airlines themselves, what sort of risks does that pose for airline operations?
Jennifer Franks Lots of risks can be posed. You know, not understanding the intended purpose of the functionality of a system, the interconnected agreements with the system. If you think about this aviation security and responsibly what TSA does, generally you’re thinking about ground transportation and what’s happening in the airports. But once a passenger gets on that airplane, and their airplane is set to back up from the gate and start to navigate its way through the concourse and to get into the air. There are a lot of interconnected systems and processes from what TSA is managing to what FAA is managing. And some of those very appropriate level of security systems and controls could have identified risk or maybe unidentified risk and threats to them if we’re not properly assigning the roles and responsibilities and addressing those different security measures that need to be addressed.
Terry Gerton The report identifies a number of findings around agency roles as we’ve just been discussing, but also budgeting and strategy. Walk us through the findings and what might’ve been at the top of the priority list here.
Jennifer Franks yes. So with the findings, you know, well, first with our objectives, rather, I will start there. Our objectives were really to hone in on the extent of their roles and responsibilities. But then the Authorization Act asked us to look at the budget request for the FAA and to just understand how they were managing cybersecurity funds. And from there to the extent to where they were following their own cybersecurity-related strategies to implement some of those roles and responsibilities and the implementation efforts and the continuous monitoring and just being better prepared for the adverse reactions should rather something occur. And what it is we were finding is a budget conversation in cybersecurity is very critical these days. You have to understand the ask and then what was appropriated and then how that money is spent. And what it is we’re finding is from fiscal years ’24 to 2026, FAA had requested between $42 million and $11 billion just on the management of cybersecurity and aviation controls. But what it is we were finding is that how they were managing the funds or just being a little bit less clear and transparent in the research and development areas was a bit of a concern. So we do have a recommendation for them to improve their transparency, rather, around the budget, because to understand how you’re managing your information, how you are managing the tools and the services and technology from an inception to a continual maintenance phase is critically important because every year with cybersecurity, your budget does inflate with the variances of threats and risks that you have to assess. But we have to understand the what was and the what is so that we can estimate, if you are appropriately aligning the resources as they should be.
Terry Gerton Jennifer Franks is the director of GAO Center for Enhanced Cybersecurity. Jennifer, one of the other things you call out is the FAA’s implementation and monitoring of its cybersecurity strategy. Where does that come into play here as you’re assessing risks and reliability?
Jennifer Franks So that’s a good question. So what it is we were finding was, FAA had not fully implemented some of the objectives supporting its cybersecurity strategy and looking at the goals to really protect and defend its networks and systems. And what’s inherently important is, you can have a procedure or some guidance and guardrails in place to navigate the what is, but unless you fully implement all of the necessary controls, you’re gonna have gaps in your processing. So there were seven objectives that FAA did outline that they needed to have support for in their cybersecurity efforts. But our assessment revealed that only three of the seven were actually adhered to. And the three that were really adhered to were their efforts to improve cyber threat intelligence collection and the processing of capabilities. We’re looking at improving capabilities for detection and mitigation of threats, which are very important because we want to be able to discern what’s coming and how to protect, and then leveraging cybersecurity research and development. But what we found, which is where we end up having some recommendations are, we have to improve our cybersecurity monitoring and our detection and our response capabilities. We have to look at our privileged user controls, those access controls of who can access these systems. It. And how often are they actually performing the services that they need to be performing when. So getting into more of those zero trust architectural principles that really help us to refine some of the security controls that are needed to enhance the environment was really critical in that area we made a recommendation.
Terry Gerton You’ve been talking primarily about findings here with the FAA. Did TSA just ace the test or were there some issues that you found with them as well?
Jennifer Franks Definitely did not ace the test and they do have one recommendation. And it really does stem from working with the stakeholders and understanding more of how cybersecurity is managed between TSA and FAA. So their recommendation was just one. It was primarily centered around that cybersecurity roadmap where they really need to clearly define their roles and responsibilities for the entities that are responsible for carrying out aviation cybersecurity. And then really looking to share that information with the pertinent stakeholders so that they know the responsibilities that TSA does provide.
Terry Gerton Jennifer, of those five recommendations, the agencies agreed with all of them, which doesn’t always happen on a GSA report. But with that kind of alignment, what do you hope then that Congress takes from this in terms of policy direction and guidance? Because again, you’re dealing with really important agencies, but they do cross departments And that makes this collaboration even more complicated.
Jennifer Franks It’s very complicated and one of the shining spots right now is that no threat has happened that mounted itself into a major event, a major cyber threat that impacted their traffic control or even ground transportation that bridges that collaboration between TSA and FAA. But we have to stay ready to get ready. We don’t know when, if, and how that vulnerability can occur. And if you’re looking at some of our recommendations and thinking about what Congress can do next, because this was a part of an authorization act, so this legislation came from Congress. We have to stay on the cutting edge of making sure that they implement these recommendations. And yes, we went in and did a subset review of some of the systems in these areas, but holistically in their environment for managing and navigating. All of the aircraft that is traveling across the globe, we need to be responsible for making sure that the configuration baseline of their agency is implementing these recommendations throughout so that if something occurs, we have the utmost sophisticated controls in place to perhaps prevent something catastrophically from occurring.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

