Skip to main content
Date Issued
Submitting OIG
Department of Transportation OIG
Other Participating OIGs
Department of Transportation OIG
Agencies Reviewed/Investigated
Department of Transportation
Components
Federal Aviation Administration
Report Number
IT2020039
Report Description

THE DEPARTMENT HAS DETERMINED THAT THIS REPORT CONTAINS SENSITIVE SECURITY INFORMATION (SSI) that is controlled under 49 CFR parts 15 and 1520 to protect Sensitive Security Information exempt from public disclosure. For U.S. Government agencies, public disclosure is governed by 5 U.S.C. 552 and 49 CFR parts 15 and 1520. A redacted version of the report will be posted here on our website when it is available. What We Looked AtThe Federal Aviation Administration (FAA) operates up to 172 Terminal Radar Approach Control (TRACON) facilities, which provide air traffic control services to pilots in the airspace immediately surrounding major airports. Currently, air traffic controllers use the Standard Terminal Automation Replacement System (STARS) to provide critical air traffic services at the 11 largest TRACONs, which handle about 33 percent of all TRACON traffic in the United States. Effective security controls and contingency plans at these 11 facilities are critical to maintaining the safety and security of the National Airspace System. Accordingly, we initiated this audit to (1) assess FAA’s identification and mitigation of security risks in STARS and (2) determine whether FAA’s contingency planning limits the effects caused by the loss of STARS operations at large TRACON facilities during emergencies. What We FoundFAA is identifying STARS’ security risks but is not mitigating vulnerabilities in a timely manner. In March 2019, for example, FAA found vulnerabilities in 53 of 73 STARS security controls but did not meet its own schedule for remediating them. DOT policy requires timely remediation of vulnerabilities to reduce the risk that an attacker could gain unauthorized access to mission-critical systems. In addition, the Agency’s STARS incident response policy does not comply with Federal requirements, and we found security control weaknesses that could make it harder for the Agency to ensure the confidentiality, integrity, and availability of STARS. Finally, FAA’s contingency plans for three large TRACONS are not sufficient to maintain continuity of air traffic operations during unplanned outages, as Agency policy requires. Our RecommendationsWe made 11 recommendations and consider recommendations 1–9 and 11 resolved but open pending completion of FAA’s planned actions. In accordance with DOT Order 8000.1C, we have asked the Agency to provide additional information on its planned actions for recommendation 10 within 30 days of the date of this report. 

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
0
Questioned Costs
$0
Funds for Better Use
$0

Open Recommendations

This report has 2 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
10 Yes $0 $0

Sensitive information redacted

11 Yes $0 $0

Sensitive information redacted

Department of Transportation OIG

United States