Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
1ST SESSION
S. 2181
To require the disclosure of information relating to cyberattacks on aircraft
systems and maintenance and ground support systems for aircraft, to
identify and address cybersecurity vulnerabilities to the United States
commercial aviation system, and for other purposes.
IN THE SENATE OF THE UNITED STATES
JULY 18, 2019
Mr. MARKEY (for himself and Mr. BLUMENTHAL) introduced the following
bill; which was read twice and referred to the Committee on Commerce,
Science, and Transportation
A BILL
To require the disclosure of information relating to
cyberattacks on aircraft systems and maintenance and
ground support systems for aircraft, to identify and ad-
dress cybersecurity vulnerabilities to the United States
commercial aviation system, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Cybersecurity Stand-
4
ards for Aircraft to Improve Resilience Act of 2019’’ or
5
the ‘‘Cyber AIR Act’’.
6
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
2
•S 2181 IS
SEC. 2. DEFINITIONS.
1
In this Act:
2
(1) COVERED AIR CARRIER.—The term ‘‘cov-
3
ered air carrier’’ means an air carrier or a foreign
4
air carrier (as those terms are defined in section
5
40102 of title 49, United States Code).
6
(2)
COVERED
MANUFACTURER.—The
term
7
‘‘covered manufacturer’’ means an entity that—
8
(A) manufactures or otherwise produces
9
aircraft and holds a production certificate under
10
section 44704(c) of title 49, United States
11
Code; or
12
(B) manufactures or otherwise produces
13
electronic control, communications, mainte-
14
nance, or ground support systems for aircraft.
15
(3) CYBERATTACK.—The term ‘‘cyberattack’’
16
means the unauthorized access to aircraft electronic
17
control or communications systems or maintenance
18
or ground support systems for aircraft, either wire-
19
lessly or through a wired connection.
20
(4) CRITICAL SOFTWARE SYSTEMS.—The term
21
‘‘critical software systems’’ means software systems
22
that can affect control over the operation of an air-
23
craft.
24
(5) ENTRY
POINT.—The term ‘‘entry point’’
25
means the means by which signals to control a sys-
26
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
3
•S 2181 IS
tem on board an aircraft or a maintenance or
1
ground support system for aircraft may be sent or
2
received.
3
SEC. 3. DISCLOSURE OF CYBERATTACKS BY THE AVIATION
4
INDUSTRY.
5
(a) IN GENERAL.—Not later than 270 days after the
6
date of the enactment of this Act, the Secretary of Trans-
7
portation shall prescribe regulations requiring covered air
8
carriers and covered manufacturers to disclose to the Fed-
9
eral Aviation Administration any attempted or successful
10
cyberattack on any system on board an aircraft, whether
11
or not the system is critical to the safe and secure oper-
12
ation of the aircraft, or any maintenance or ground sup-
13
port system for aircraft, operated by the air carrier or pro-
14
duced by the manufacturer, as the case may be.
15
(b) USE OF DISCLOSURES BY THE FEDERAL AVIA-
16
TION ADMINISTRATION.—The Administrator of the Fed-
17
eral Aviation Administration shall use the information ob-
18
tained through disclosures made under subsection (a) to
19
improve the regulations required by section 4 and to notify
20
air carriers, aircraft manufacturers, and other Federal
21
agencies of cybersecurity vulnerabilities in systems on
22
board an aircraft or maintenance or ground support sys-
23
tems for aircraft.
24
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
4
•S 2181 IS
SEC. 4. INCORPORATION OF CYBERSECURITY INTO RE-
1
QUIREMENTS FOR AIR CARRIER OPERATING
2
CERTIFICATES AND PRODUCTION CERTIFI-
3
CATES.
4
(a) REGULATIONS.—Not later than 270 days after
5
the date of the enactment of this Act, the Secretary of
6
Transportation, in consultation with the Secretary of De-
7
fense, the Secretary of Homeland Security, the Attorney
8
General, the Federal Communications Commission, and
9
the Director of National Intelligence, shall prescribe regu-
10
lations to incorporate requirements relating to cybersecu-
11
rity into the requirements for obtaining an air carrier op-
12
erating certificate or a production certificate under chap-
13
ter 447 of title 49, United States Code.
14
(b) REQUIREMENTS.—In prescribing the regulations
15
required by subsection (a), the Secretary shall—
16
(1) require all entry points to the electronic sys-
17
tems of each aircraft operating in United States air-
18
space and maintenance or ground support systems
19
for such aircraft to be equipped with reasonable
20
measures to protect against cyberattacks, including
21
the use of isolation measures to separate critical
22
software systems from noncritical software systems;
23
(2) require the periodic evaluation of the meas-
24
ures described in paragraph (1) for security
25
vulnerabilities using best security practices, includ-
26
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
5
•S 2181 IS
ing the appropriate application of techniques such as
1
penetration testing, in consultation with the Sec-
2
retary of Defense, the Secretary of Homeland Secu-
3
rity, the Attorney General, the Federal Communica-
4
tions Commission, and the Director of National In-
5
telligence; and
6
(3) require the measures described in para-
7
graph (1) to be periodically updated based on the re-
8
sults of the evaluations conducted under paragraph
9
(2).
10
SEC. 5. MANAGING CYBERSECURITY RISKS OF CONSUMER
11
COMMUNICATIONS EQUIPMENT.
12
(a) IN GENERAL.—The Commercial Aviation Com-
13
munications Safety and Security Leadership Group estab-
14
lished by the memorandum of understanding between the
15
Department of Transportation and the Federal Commu-
16
nications Commission entitled ‘‘Framework for DOT–
17
FCC Coordination of Commercial Aviation Communica-
18
tions Safety and Security Issues’’ and dated January 29,
19
2016 (in this section known as the ‘‘Leadership Group’’),
20
shall be responsible for evaluating the cybersecurity
21
vulnerabilities of broadband wireless communications
22
equipment designed for consumer use on board aircraft
23
operated by covered air carriers that is installed before,
24
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
6
•S 2181 IS
on, or after, or is proposed to be installed on or after,
1
the date of the enactment of this Act.
2
(b) RESPONSIBILITIES.—To address cybersecurity
3
risks arising from malicious use of communications tech-
4
nologies on board aircraft operated by covered air carriers,
5
the Leadership Group shall—
6
(1) ensure the development of effective methods
7
for preventing foreseeable cyberattacks that exploit
8
broadband wireless communications equipment de-
9
signed for consumer use on board such aircraft; and
10
(2) require the implementation by covered air
11
carriers, covered manufacturers, and communica-
12
tions service providers of all technical and oper-
13
ational security measures that are deemed necessary
14
and sufficient by the Leadership Group to prevent
15
cyberattacks described in paragraph (1).
16
(c) REPORT REQUIRED.—Not later than one year
17
after the date of the enactment of this Act, and annually
18
thereafter, the Leadership Group shall submit to the Com-
19
mittee on Commerce, Science, and Transportation of the
20
Senate and the Committee on Transportation and Infra-
21
structure of the House of Representatives a report on—
22
(1) the technical and operational security meas-
23
ures developed to prevent foreseeable cyberattacks
24
that exploit broadband wireless communications
25
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
7
•S 2181 IS
equipment designed for consumer use on board air-
1
craft operated by covered air carriers; and
2
(2) the steps taken by covered air carriers, cov-
3
ered manufacturers, and communications service
4
providers to implement the measures described in
5
paragraph (1).
6
Æ
VerDate Sep 11 2014
22:29 Jul 23, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6301
E:\BILLS\S2181.IS
S2181
kjohnson on DSK79L0C42 with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.