Skip to main content

Flight Controller Link Security Statement

Describes the APS standard for creating only attended links and avoiding the use of unattended links to controllers,

APS Position on Flight Modem Controller Links

APS's standard practice is to create controller access links for Flight modems only when remote access is actively required. This approach aligns with accepted SSH security principles and cybersecurity best practices, which are designed around attended, time-limited connections rather than persistent or long-term access.

APS recognizes that unattended or continuously enabled controller links create unnecessary cybersecurity risk by increasing the system's attack surface and providing a continuous pathway to critical control assets. If credentials are compromised or vulnerabilities are discovered, long-term links may be leveraged to gain unauthorized access, move laterally to other controllers within the environment, or introduce malicious software into the control network.

These risks extend beyond the target controller and can impact other connected controllers and devices within the broader operational technology infrastructure. To minimize exposure while still enabling effective commissioning and support, APS recommends that controller links be established only when needed, maintained only for the duration of the required activity, and removed immediately upon completion. This least-privilege approach improves accountability, reduces security exposure, and helps protect system integrity.

Accordingly, APS supports time-limited attended connections, with the maximum duration for any controller link limited to 24 hours only during initial startup and commissioning activities, after which access should be terminated and re-established only when future support activities require it. This practice balances operational efficiency with the highest level of security and protection for our customers' control systems.

APS is actively protecting your operational assets using a security-first approach.

END of Statement

FAQs

Q: My workflow is such that i need long term links, What do you propose?

A: We can provide remote access whenever you need it, but we don't recommend permanent controller connections. A persistent link increases cybersecurity risk and creates a potential pathway into your control environment 24/7. Our goal is to give you the benefits of remote support while minimizing unnecessary exposure.

(House Analogy) Think of it like unlocking the front door to your house when a technician arrives rather than leaving it unlocked all year.

Did this answer your question?