Product and Device Security

Assessment of drone or component to ensure it has been designed, developed, and manufactured to assure the safety and security of data used to support UxS Systems and mission operations. Security controls to be tested will be based on specific operational context, application and criticality of the system.

  • Cryptography and Trust. Controls provide reasonable assurance that mechanisms for maintaining cryptographic primitives are secure and that cryptographic protocols and algorithms are implemented in accordance with NIST standards.
  • Data at Rest. Controls provide reasonable assurance that data stored within the UxS System or within removable media are protected against deletion, eavesdropping and tampering.
  • Regulatory Compliance. Controls provide reasonable assurance that UxS System operations comply with applicable laws and regulations and that the UxS System manufacturer understands risks based on the operational context of the UxS System.
  • Privacy and Anonymity. Controls provide reasonable assurance that the manufacturer understands and mitigates data that may result in privacy loss or allow unauthorized tracking of UxS System occupants.
  • Resilience. Controls provide reasonable assurance that UxS Systems can recover from cyber security events and can continue operation in a safe manner.
  • Secure Autonomy. Controls provide reasonable assurance that UxS Systems can make assured autonomy decisions in support of perceptions, sense and avoid, path/route planning, navigation and control.
  • Secure Development and Integration. Controls provide reasonable assurance that manufacturers understand and mitigate threats and weaknesses during the design and development of a UxS System.
  • Secure Remote Interfaces. Controls provide reasonable assurance that interfaces between the UxS System and remote systems are encrypted, integrity protected and authenticated.
  • Secure Updates. Controls provide reasonable assurance that UxS Systems can be securely updated.
  • UxS System Identity. Controls provide reasonable assurance that UxS Systems are provisioned with a globally-unique identifier.
  • UxS System Platform Security. Controls provide reasonable assurance that UxS Systems are secure from local tampering and exploitation.