On the Role of SecRAM Catalogues in ATM Cyber Risk Assessment and Improvement Opportunities

Davide Martintoni, Valerio Senni, Gurjot Singh Gaba, Andrei Gurtov · 2025

Current Air Traffic Management (ATM) systems are undergoing significant evolution due to increased traffic volumes, the introduction of diverse airborne systems such as Unmanned Aerial Vehicles (UAVs), technological advancements, and the potential to optimize operations through data-driven approaches. These advancements offer benefits in terms of efficiency, safety, and sustainability, but they also expose the systems to heightened cybersecurity risks. This paper analyzes the Security Risk Assessment Methodology (SecRAM) proposed by SESAR, focusing specifically on its use of complementary catalogs of threats and vulnerabilities. By validating the SecRAM approach in a contemporary ATM scenario, this paper identifies gaps in the framework that could be addressed to better meet the security needs of a modern and complex ATM ecosystem. Finally, this work proposes a set of enhancements to the SecRAM catalogs that will enable security professionals to design and develop secure and resilient modern ATM environments.

Read the paper · More papers on PaperTik