Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · U.S. Code · Title 49 - TRANSPORTATION · CHAPTER 401— GENERAL PROVISIONS · § 40131

§ 40131. National airspace system cyber threat management process

1,494 words·~7 min read·/usc/title-49/section-40131

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

(a)Establishment.— The Administrator of the Federal Aviation Administration, in consultation with the heads of other agencies as the Administrator determines necessary, shall establish a national airspace system cyber threat management process to protect the national airspace system cyber environment, including the safety, security, and efficiency of air navigation services provided by the Administration.
(b)Issues To Be Addressed.— In establishing the national airspace system cyber threat management process under subsection (a), the Administrator shall, at a minimum—
(1)monitor the national airspace system for significant cybersecurity incidents;
(2)in consultation with appropriate Federal agencies, evaluate the cyber threat landscape for the national airspace system, including updating such evaluation on both annual and threat-based timelines;
(3)conduct national airspace system cyber incident analyses;
(4)create a cyber common operating picture for the national airspace system cyber environment;
(5)coordinate national airspace system significant cyber incident responses with other appropriate Federal agencies;
(6)track significant cyber incident detection, response, mitigation implementation, recovery, and closure;
(7)establish a process, or utilize existing processes, to share relevant significant cyber incident data related to the national airspace system;
(8)facilitate significant cybersecurity reporting, including through the Cybersecurity and Infrastructure Agency; and
(9)consider any other matter the Administrator determines appropriate.
(c)Definitions.— In this section:
(1)Cyber common operating picture.— The term “cyber common operating picture” means the correlation of a detected cyber incident or cyber threat in the national airspace system and other operational anomalies to provide a holistic view of potential cause and impact.
(2)Cyber environment.— The term “cyber environment” means the information environment consisting of the interdependent networks of information technology infrastructures and resident data, including the internet, telecommunications networks, computer systems, and embedded processors and controllers.
(3)Cyber incident.— The term “cyber incident” means an action that creates noticeable degradation, disruption, or destruction to the cyber environment and causes a safety or other negative impact on operations of—
(A)the national airspace system;
(B)civil aircraft; or
(C)aeronautical products and articles.
(4)Cyber threat.— The term “cyber threat” means the threat of an action that, if carried out, would constitute a cyber incident or an electronic attack.
(5)Electronic attack.— The term “electronic attack” means the use of electromagnetic spectrum energy to impede operations in the cyber environment, including through techniques such as jamming or spoofing.
(6)Significant cyber incident.— The term “significant cyber incident” means a cyber incident, or a group of related cyber incidents, that the Administrator determines is likely to result in demonstrable harm to the national airspace system of the United States.
(Added Pub. L. 118–63, title III, § 393(a), May 16, 2024, 138 Stat. 1144.)
Connections8 cite this · traces to 5
3 references not yet in our index
  • 138 Stat. 1144
  • 138 Stat. 1055
  • 138 Stat. 1145
Citation graph
cites case law
§ 40131
National airspace system cyber threat management process
Pub. L.×3
Stat. Comp.×3
U.S.C.×2
Stat.138 Stat. 1144
Stat.138 Stat. 1055
Stat.138 Stat. 1145
Cites 8Cited by 8 across 3 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.