My Account Log in

2 options

Information security and cybersecurity at the Federal Aviation Administration : challenges and control efforts / Victor Morris, editor.

EBSCOhost Ebook Business Collection Available online

View online

Ebook Central Academic Complete Available online

View online
Format:
Book
Contributor:
Morris, Victor, editor.
Series:
Defense, security and strategy series.
Defense, Security and Strategy
Language:
English
Subjects (All):
United States. Federal Aviation Administration--Communication systems--Security measures.
United States.
Computer security--Government policy--United States.
Computer security.
Telecommunication--Security measures--United States.
Telecommunication.
Physical Description:
1 online resource (102 p.)
Place of Publication:
New York : Nova Publishers, 2015.
Language Note:
English
Summary:
While the Federal Aviation Administration (FAA) has taken steps to protect its air traffic control systems from cyber-based and other threats, significant security control weaknesses remain, threatening the agency's ability to ensure the safe and uninterrupted operation of the national airspace system (NAS). These include weaknesses in controls intended to prevent, limit, and detect unauthorized access to computer resources, such as controls for protecting system boundaries, identifying and authenticating users, authorizing users to access systems, encrypting sensitive data, and auditing and monitoring activity on FAA's systems. Additionally, shortcomings in boundary protection controls between less-secure systems and the operational NAS environment increase the risk from these weaknesses. The objective of this book is to evaluate the extent to which FAA has effectively implemented information security controls to protect its air traffic control systems. This book also identifies the cybersecurity challenges facing FAA as it shifts to the NextGen ATC system and how FAA has begun addressing those challenges; and assesses the extent to which FAA and its contractors, in the acquisition of NextGen programs, have followed federal guidelines for incorporating cybersecurity controls.
Contents:
INFORMATION SECURITY AND CYBERSECURITY AT THE FEDERAL AVIATION ADMINISTRATION CHALLENGES AND CONTROL EFFORTS ; INFORMATION SECURITY AND CYBERSECURITY AT THE FEDERAL AVIATION ADMINISTRATION CHALLENGES AND CONTROL EFFORTS ; Library of Congress Cataloging-in-Publication Data; CONTENTS ; PREFACE ; Chapter 1 INFORMATION SECURITY: FAA NEEDS TO ADDRESS WEAKNESSES IN AIR TRAFFIC CONTROL SYSTEMS ; ABBREVIATIONS ; WHY GAO DID THIS STUDY ; WHAT GAO RECOMMENDS ; WHAT GAO FOUND ; BACKGROUND ; Many Networked Information Systems Support NAS Operations
Information Security Is Critical to the Nation's Critical Infrastructures, Including Air Traffic Control Systems Several Organizations within FAA Are Responsible for Information Security; Requirements for Ensuring the Security of Federal Information Systems Are Established in Law and Guidance ; SECURITY WEAKNESSES PLACE AIR TRAFFIC CONTROL SYSTEMS AT RISK ; FAA Did Not Consistently Control Access to NAS Systems ; Although Control Mechanisms Were Put in Place, FAA Did Not Always Adequately Protect the Boundary of NAS Systems
FAA Did Not Consistently Implement Controls for Identifying and Authenticating Users of NAS SystemsFAA Did Not Always Ensure Users Were Properly Authorized to Access NAS Systems ; Sensitive Data Were Not Always Sufficiently Encrypted ; FAA Did Not Consistently Implement Sufficient Audit and Monitoring Controls; While Background Investigations Were Conducted in Accordance with Policy, Changes to Network Systems and Software Were Not Always Properly Controlled ; FAA Conducted Background Investigations in Accordance with Policy
FAA Did Not Always Properly Control Changes to Network Devices or Ensure Key Systems Were Fully Patched FAA Did Not Fully Implement Its Information Security Program, Limiting the Effectiveness of Information Security Controls; Policies and Procedures Were Not Always Complete ; Users with Significant Security Responsibilities Had Not Always Received Required Security Training ; Security Controls Were Not Always Tested Sufficiently ; Identified Security Weaknesses Were Not Always Addressed in a Timely Fashion ; NAS Incident Detection and Response Activities Were Limited
Contingency Plans Were Not Always Complete or Adequately Tested Inadequate Agency-Wide Information Security Risk Management Processes Contribute to Weaknesses in Security Controls and Security Management ; CONCLUSION ; RECOMMENDATIONS FOR EXECUTIVE ACTION ; AGENCY COMMENTS AND OUR EVALUATION ; APPENDIX I: OBJECTIVE, SCOPE, AND METHODOLOGY ; End Notes ; End Notes for Appendix I; Chapter 2 AIR TRAFFIC CONTROL: FAA NEEDS A MORE COMPREHENSIVE APPROACH TO ADDRESS CYBERSECURITY AS AGENCY TRANSITIONS TO NEXTGEN* ; WHY GAO DID THIS STUDY ; WHAT GAO RECOMMENDS ; WHAT GAO FOUND ; ABBREVIATIONS
BACKGROUND
Notes:
Includes index.
Description based on print version record.
ISBN:
1-63483-313-9

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account