Skip to content

DO-326A sensor systems

DO-326A airworthiness security evidence support for sensor systems

This support reviews a sensor system's airworthiness security evidence against the DO-326A process, alongside the ARP4754B development assurance the sensor is built under. It is run by the sensor supplier or the installing modifier before submittal or during a finding. The work covers the security scoping, the threat conditions around configuration, calibration, and maintenance-access paths, the integrity of the output the sensor feeds downstream, and the measures argued for each threat. You get a standards map to the DO-326A objectives, a ranked evidence gap list, and a closure sequence.

When this review is needed

  • A sensor system is being submitted and its maintenance-access paths have not been assessed for DO-326A.
  • An authority questioned whether a stored calibration or configuration value could be altered without detection.
  • A configuration or calibration loading interface was added and its threat conditions were never characterized.
  • The sensor feeds systems whose security case assumed its output was trustworthy without stating why.

The problem

A sensor's security exposure is quieter than a radio's: it is the stored configuration and calibration that shape its output, and the maintenance interface that can reach them. A calibration value altered through a service port changes what the sensor reports without any RF or network attack, and the change can persist unnoticed because nothing on the aircraft re-derives it. When the DO-326A case treats the sensor as a sealed source of truth, it never asks how the configuration is protected or who can write to it, and the maintenance path becomes the unmodeled way in.

What gets reviewed

  • Security scoping of the sensor system including its maintenance and loading interfaces
  • Threat conditions on stored configuration and calibration values
  • Integrity and write-protection of the maintenance-access path
  • Integrity of the output the sensor feeds to downstream consumers
  • Security measures and the effectiveness argument for each threat condition
  • Security-derived requirements fed back into the sensor equipment baseline

What gets validated

  • Stored configuration and calibration values have integrity protection appropriate to their threat conditions
  • The maintenance-access path controls who can write to those values and appears in the threat model
  • Each threat condition maps to a security measure with an effectiveness argument
  • Downstream trust in the sensor output is supported by an integrity argument, not an assumption
  • Security-derived requirements appear in the equipment baseline and trace to verification

Evidence normally required

  • The DO-326A security plan and scoping rationale for the sensor item
  • The threat condition and security risk assessment for configuration and maintenance functions
  • Interface descriptions for maintenance access, calibration loading, and output paths
  • Descriptions of integrity and write-protection controls on stored values
  • The equipment requirements baseline and its security-derived requirements

Common discrepancies

  • Stored calibration values with no integrity protection against alteration through the service port
  • A maintenance-access interface outside the security scoping
  • Downstream systems trusting the sensor output with no integrity argument to back it
  • A configuration loading path present in the design but absent from the threat model

What is at stake

A sensor whose configuration integrity is unprotected can be made to report plausible but wrong values through its own maintenance interface, and every function that trusts its output inherits the corruption. If an authority reads that gap, the response has to establish write-protection or detection on the stored values and justify the maintenance-access controls, which is harder once the interface is fielded and the downstream trust is already designed in.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Scope the access paths

Enumerate the maintenance and calibration-loading interfaces and confirm each is in the security scope.

02

Protect the stored values

Assess integrity and write-protection on configuration and calibration data against their threat conditions.

03

Trace downstream trust

Check that systems consuming the sensor output rest on a stated integrity argument, not an assumption.

04

Sequence the closure

Secure the stored values and access path first, then rank the remaining gaps.

What the buyer receives

  • A standards map to the DO-326A objectives for the sensor item
  • A ranked evidence gap list centered on configuration and maintenance-access integrity
  • A closure sequence that secures the stored values and access path first

Who uses the output

  • Certification leads preparing the sensor submittal or finding response
  • Security engineers assessing configuration integrity and maintenance access
  • Compliance managers tracking which access-path gaps still block the package

How the work fits into the transaction or program

This review works alongside the ARP4754B development assurance for the sensor and inside the aircraft-level security case DO-326A governs. It confirms the stored configuration and the maintenance path that reaches it are protected, so the sensor enters the compliance matrix without a quiet write path that downstream trust cannot see.

Start with a single asset

Confirm requirements trace through verification.

Jurisdiction-specific considerations

The FAA and EASA both apply DO-326A, but they differ on how strictly they treat maintenance-access controls, and EASA more often asks for detection of altered stored values rather than access restriction alone. The map notes where an access-control argument accepted by one authority may draw a request for tamper detection from the other.

Regulatory limits

This work maps and checks the airworthiness security evidence against DO-326A. It does not test the maintenance interface, attempt any tampering, or make an airworthiness determination. Those responsibilities stay with the applicant and the certifying authority.

What this review does not cover

  • Tampering trials or penetration testing of the sensor
  • Authoring the threat assessment or security measures from scratch
  • Any determination that the sensor system is airworthy or approvable

Specific to this review

  • A sensor's main DO-326A exposure is the stored configuration and calibration, not a live network attack, because those values quietly shape every output.
  • The maintenance-access port is the sensor's most common unmodeled way in, since it is designed for service rather than treated as a threat surface.
  • Downstream systems that trust a sensor output need an integrity argument behind that trust; without one, a tampered configuration propagates unchecked.

Sources

Frequently asked questions

Why focus on the maintenance port rather than a network attack on the sensor?

Because the sensor's stored calibration and configuration shape everything it reports, and the maintenance interface is the path that can reach them. A value altered there persists silently and corrupts every downstream consumer. DO-326A wants that interface treated as a threat surface, which is exactly where sensor cases tend to be thin.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.