SACAA outlines air cargo cyber-reporting scope

Unauthorised access, malware, ransomware, data breaches and disruption of critical ICT systems could fall within air cargo cybersecurity reporting requirements, according to the South African Civil Aviation Authority (SACAA).

The authority said incidents that could compromise aviation-related systems, networks, information or data fall within the requirements. It stressed that the examples were illustrative rather than an exhaustive list of reportable incidents.

The clarification follows the Thirty-Third Amendment of the Civil Aviation Regulations, published in Government Gazette No 55226 on August 21. The amendment requires regulated agents and known consignors to report cybersecurity incidents to the Director of Civil Aviation within 48 hours of becoming aware of them.

Some regulated agents and known consignors may need to amend their security programmes and internal procedures to comply, SACAA communications and stakeholder relations manager Sisa Majola told Freight News.

Majola said designated officials might rely on ICT departments to identify and communicate incidents. Internal processes must therefore ensure that information reaches the relevant officials quickly enough for the organisation to meet the reporting deadline.

The reporting clock starts when the regulated entity becomes aware of a reportable cybersecurity incident, he said.

While SACAA said established mechanisms were in place for reporting aviation safety and security occurrences, it did not specify the reporting channel in its response. Instead, it referred to the requirements and processes contained in the applicable aviation security framework.

The authority said the amendment was intended to enhance existing aviation cybersecurity requirements rather than introduce an entirely new framework.

Failure to comply with Part 108 could result in enforcement action under the Civil Aviation Act, the Civil Aviation Regulations and SACAA’s established enforcement processes.

SACAA did not identify a specific penalty for missing the 48-hour deadline, saying enforcement action would depend on the circumstances and seriousness of the case.

Majola also pointed to existing aviation cybersecurity Technical Guidance Material to support regulated entities. It covers cybersecurity culture and the development and implementation of aviation cybersecurity programmes.

© Now Media. This content is protected by copyright and may not be adapted or republished. If you would like to discuss cooperation opportunities, please contact: editor@freightnews.co.za.