Case Study

UK Civil Aviation Authority

Improving Cyber Security Oversight in the UK

In response to the evolving cyber threat landscape, the UK Civil Aviation Authority (CAA) undertook a comprehensive re-visioning of its cyber security oversight to enhance awareness of both direct and indirect cyber threats. This strategic initiative aimed to strengthen the UK CAA’s ability to safeguard aviation systems, ensuring that its oversight frameworks remain robust, adaptable, and proactive in addressing emerging cyber security risks. The project focused on refining policies and practices to maintain the highest standards of safety and security within the aviation sector.

Background

Cyber security risk profiles are dynamic, meaning those with malicious intent can quickly develop new ways of breaching cyber security. Prior to October 2019, the UK CAA cyber security audit used a prescribed questionnaire to assess compliance of the UK industry with the regulations. The regulated entities were subject to five to six audits, having their cyber security assessed under different operational activities, often duplicating tasks across operational functions.

The process was time-consuming for both the regulated entities and the regulator. The risk self-assessment did not reflect requirements specific to the entities and did not encourage proactive evaluation and preparation for potential threats. To keep pace with the changing threat landscape and promote awareness of direct and indirect cyber security threats, the UK CAA embarked on re-visioning its existing cyber security oversight.

Developing a Consistent and Efficient Cyber Security Oversight Framework for Diverse Aviation Organisations

The UK CAA had to develop a new cyber security oversight process consistent across different scopes and applicable to aviation organisations of varying size and complexity. It was essential to change the prescriptive principle of the existing oversight to enable industry entities to manage their cyber security risks effectively. This would enable them to detect cyber security incidents and minimise their impact, protecting their organisation, staff, and clients.

As part of the cyber security assessment process, aviation organisations must be able to determine and document all critical systems. At the time, the methodology to determine critical systems across operational functions did not exist. This led to additional work when entities used to assess everything that was mandatory or what they thought was critical.

The entire cyber security oversight process needed to become more efficient and effective for the regulated organisations and regulator.

Reforming Cyber Security Oversight

Working closely with the Department for Transport, industry and the National Cyber Security Centre, the UK CAA reformatted and amended the core Cyber Assessment Framework (CAF) to create the CAF for Aviation. The new framework harmonised all cyber security requirements across different regulatory scopes (safety, security, resilience) into one comprehensive cyber security framework, which became applicable to aviation organisations of different sizes and complexity.

The new framework aligned with the existing UK CAA performance-based oversight processes, encouraging aviation organisations to manage their own risks with a focus on relevant/real incidents, enabling proactive assessment of existing barriers and control levels.

The UK CAA Cyber Security Oversight Team in close collaboration with industry,  introduced guidance on how to identify critical systems, with a focus on those elements that would impact flight safety.

The UK CAA integrated cyber security assessment processes across all operational functions into one, leading to one process for aviation organisations to meet their regulatory cyber security requirements and assess their level of protection against relevant threats.

The Authority decided to outsource cyber security audits to increase efficiency and transparency, using the Qualified Entity model. CAA partnered with an accreditation and certification body to create an accreditation scheme enabling aviation organisations to access accredited cyber security auditors. To ensure compliance with the Cyber Security Oversight Process CAP1753, the Authority gives final compliance approval.

A Proportionate Approach to Risk Management and Industry Benefits

The new proportionate and effective approach to the cyber security oversight enabled the aviation organisations to manage their cyber security risks without compromising aviation safety, security or resilience.

Clear guidance on how to determine critical systems led to a reduction in the scope of work for regulated entities enabling them to focus and enhance systems relevant to their specifications. This guidance was later adopted by the EU Commission into their new Cyber Security Guidance.

The cyber security oversight process became more efficient and less time-consuming by removing duplications during the self-assessment stage and facilitating the evaluation of the cyber security regime through a single audit.

Outsourcing auditing to accredited companies brought economic benefits for industry, allowing them to choose from a large pool of competing auditors. The Authority benefitted from time savings, allowing the UK CAA cyber security experts to concentrate on improving cyber security oversight.

Go beyond compliance with expert advice by the UK CAA

We assist nations and regulated entities in surpassing compliance to exceed international aviation security standards by developing sustainable, risk-based, and proportionate frameworks. Our goal is not only to ensure that States meet their obligations but also to foster a holistic approach that embeds a risk-based strategy and a strong security culture at its core. With our internationally recognised experts, who are key contributors to the ICAO GASeP, we are uniquely positioned to provide expert advice on all aspects of aviation security regulation.

Discover how our advisory services can enhance your aviation security system

Speak to Kevin Sawyer about our services today
Get in touch
View shopping cart