Skip to content

DO-326A display systems

DO-326A airworthiness security evidence support for display systems

This support checks a cockpit display system's airworthiness security evidence against the DO-326A process, focused on the data feeding the display rather than the glass itself. It is run by the display supplier or the installing modifier before submittal or during a finding. The work reviews the security scoping, the threat conditions on the source data and update paths that populate the display, the integrity of what reaches the symbol generation, and the measures argued for each threat. You get a standards map to the DO-326A objectives, a ranked evidence gap list, and a closure sequence.

When this review is needed

  • A display system is being submitted and the integrity of its source data has not been assessed for DO-326A.
  • An authority questioned whether a corrupted or spoofed input could reach the crew as a plausible symbol.
  • A new data source or chart-loading path was added and its threat conditions were never characterized.
  • The display renders data from networks whose security scoping did not extend to the display item.

The problem

A display's DO-326A risk is not that the screen fails, it is that the screen faithfully renders bad data. The security question is whether a corrupted or spoofed input can travel up the feed and appear to the crew as a legitimate symbol, altitude, or chart. Teams that spent their attention on the software assurance of the display often left the source-data integrity to the systems that supply it, so no artifact states what the display does when a feed it trusts turns out to be tampered. The exposure hides in the handoff between supplier and integrator.

What gets reviewed

  • Security scoping of the display item including the data sources it renders
  • Threat conditions on source-data and chart or map loading paths
  • Integrity of data reaching symbol generation from upstream systems
  • The boundary between display-owned and source-owned integrity controls
  • Security measures and the effectiveness argument for each threat condition
  • Security-derived requirements fed back into the display equipment baseline

What gets validated

  • The scoping covers every data source and loading path the display renders
  • Data integrity for rendered content is enforced somewhere and that owner is explicit
  • Threat conditions cover a plausible corrupted symbol reaching the crew rather than only a blank display
  • Each threat condition maps to a security measure with an effectiveness argument
  • Security-derived requirements appear in the equipment baseline and trace to verification

Evidence normally required

  • The DO-326A security plan and scoping rationale for the display item
  • The threat condition and security risk assessment for source-data and loading paths
  • Interface descriptions for every data source the display renders
  • Descriptions of integrity controls on rendered data, wherever they sit
  • The equipment requirements baseline and its security-derived requirements

Common discrepancies

  • Source-data integrity assumed to be owned by the supplying system, with no confirmation
  • A chart or map loading path outside the display's security scoping
  • Threat conditions covering loss of display but not a corrupted rendered symbol
  • An integrity handoff between display and data source that neither party documents

What is at stake

A display that renders whatever it receives, with no integrity check on the feed, can present a misleading indication to the crew from a security cause rather than a random failure. When an authority reads that gap, the response has to establish where the data integrity is enforced and argue it is sufficient, which is awkward when the display supplier and the data-source supplier each assumed the other owned it. The unresolved handoff is where the finding lands.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Scope the data sources

Enumerate every source and loading path the display renders and confirm each is in scope.

02

Locate the integrity owner

Identify where the integrity of rendered data is enforced and make the owning system explicit.

03

Model the corrupted-symbol case

Confirm the threat conditions cover a plausible tampered symbol reaching the crew rather than only a lost display.

04

Close the handoff

Resolve the display-to-source integrity boundary first, then sequence the remaining gaps.

What the buyer receives

  • A standards map to the DO-326A objectives for the display item
  • A ranked evidence gap list centered on source-data integrity ownership
  • A closure sequence that resolves the display-to-source integrity boundary first

Who uses the output

  • Certification leads preparing the display submittal or finding response
  • Security engineers resolving where rendered-data integrity is enforced
  • Compliance managers tracking which source-data gaps still block the package

How the work fits into the transaction or program

This review sits at the boundary between the display and the systems that feed it, inside the aircraft-level security case DO-326A governs. It settles who enforces the integrity of rendered data so the display enters the compliance matrix without an unowned handoff where a corrupted feed could reach the crew.

Start with a single asset

Confirm requirements trace through verification.

Jurisdiction-specific considerations

Both the FAA and EASA apply DO-326A, but they probe the display-to-source integrity boundary with different emphasis, and EASA more often asks the display item to demonstrate its own input validation. The map notes where reliance on an upstream control accepted by one authority is likely to prompt the other to ask what the display checks itself.

Regulatory limits

This work maps and checks the airworthiness security evidence against DO-326A. It does not test the display, inject any data, or make an airworthiness determination. Those responsibilities remain with the applicant and the certifying authority.

What this review does not cover

  • Data-injection testing or penetration testing of the display
  • Authoring the threat assessment or security measures from scratch
  • Any determination that the display system is airworthy or approvable

Specific to this review

  • For displays the DO-326A concern is a faithfully rendered but tampered symbol reaching the crew, not the screen going dark.
  • Source-data integrity is the classic split responsibility, and the finding usually lands in the handoff neither the display nor the data supplier claimed.
  • A display that renders whatever it receives needs its own input validation argued, or the integrity has to be provably enforced upstream.

Sources

Frequently asked questions

Doesn't the system supplying the data own its integrity, not the display?

That is often the intent, but it has to be stated and verified. The frequent finding is that the display assumed the source enforced integrity while the source assumed the display validated its input, so no one did. DO-326A needs that boundary owned explicitly, which is the first thing this review settles.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.