Overview
In the rapidly evolving landscape of aviation cybersecurity, ensuring compliance with standards like DO-356 (Airworthiness Security Methods and Considerations) is critical for mitigating risks in networked avionics systems. Using Ansys and Systems Theoretic Process Analysis (STPA), streamlines safety and enhances system security and aviation cybersecurity with DO-356 standard compliance.
Focusing on a real-world use case for a Class 3 installed Electronic Flight Bag (EFB) system, the session will demonstrate how security engineers can start from functional requirements and physical architecture to identify threats, assess risks, and derive security requirements. Drawing from Astronautics' proven methodology, developed in collaboration with MIT Lincoln Laboratory for the FAA's Aircraft Systems Information Security/Protection (ASISP) program, the presentation will align with Systems Theoretic Process Analysis (STPA) principles. Key steps include defining system function statements, modeling control structures, building attack trees, evaluating adversary capabilities and safety impacts, and generating traceable risk charts and reports.