计算机安全
空中交通管制
航空
问责
代理(哲学)
政府(语言学)
控制(管理)
最佳实践
信息安全管理
国家安全
机场保安
信息安全
信息系统
安全控制
业务
安全信息和事件管理
工程类
计算机科学
政治学
云安全计算
法学
云计算
哲学
语言学
电气工程
认识论
人工智能
航空航天工程
作者
Gregory C. Wilshusen,Nabajyoti Barkakati,Gerald L. Dillingham
摘要
In support of its mission, the Federal Aviation Administration (FAA) relies on the national airspace system (NAS)—one of the nation’s critical infrastructures—which is comprised of air traffic control systems, procedures, facilities, aircraft, and people who operate and maintain them. Given the critical role of the NAS and the increasing connectivity of FAA’s systems, it is essential that the agency implement effective information security controls to protect its air traffic control systems from internal and external threats. The Government Accountability Office (GAO) was asked to review FAA’s information security program. Specifically, the objective of this review was to evaluate the extent to which FAA had effectively implemented information security controls to protect its air traffic control systems. To do this, GAO reviewed FAA policies, procedures, and practices and compared them to the relevant federal law and guidance; assessed the implementation of security controls over FAA systems; and interviewed officials. This is a public version of a report containing sensitive security information. Information deemed sensitive has been redacted. GAO is making 17 recommendations to FAA to fully implement its information security program and establish an integrated approach to managing information security risk. In a separate report with limited distribution, GAO is recommending that FAA take 168 specific actions to address weaknesses in security controls. In commenting on a draft of this report, FAA concurred with GAO’s recommendations.
科研通智能强力驱动
Strongly Powered by AbleSci AI