Join our Newsletter — 33% off our NHI Course

What breaks when third-party access is not reviewed in civil aviation?

Supplier identities can retain roles, integrations, and federated access long after the business need changed. That creates hidden trust paths into airline systems and makes normal vendor activity hard to distinguish from compromise. The failure is not just visibility. It is lifecycle drift across the external access chain.

Why Third-Party Access Reviews Matter in Civil Aviation

Civil aviation depends on a dense web of suppliers, maintainers, handlers, software vendors, and integrations that often hold access far beyond the original business need. When third-party access is not reviewed, roles, API keys, federation trusts, and service accounts can persist unnoticed across airline, airport, and MRO environments. That turns routine vendor connectivity into a long-lived trust path that is hard to distinguish from compromise.

The risk is not limited to bad credentials. Unreviewed external access can expose booking systems, maintenance platforms, operational data, and identity infrastructure to lateral movement, hidden privilege retention, and weak offboarding. NHI Management Group has documented how widely external exposure persists in practice: 92% of organisations expose NHIs to third parties, according to the Ultimate Guide to NHIs. In civil aviation, that translates into supplier trust becoming operational debt.

Current guidance from the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls points to recurring review, least privilege, and lifecycle control as baseline expectations, but aviation teams often treat vendor onboarding as the control point and ignore the downstream drift. In practice, many security teams discover this only after a supplier account is still active long after the contract, ticket, or maintenance window has ended.

How Access Drift Breaks Aviation Operations and Security Controls

Third-party access breaks when the organisation assumes vendor identity is static. Civil aviation environments are especially exposed because vendors frequently need seasonal, event-driven, or aircraft-specific access, which makes permissions change often and makes manual oversight fragile. The right model is continuous review, not one-time approval.

Operationally, that means mapping each external identity to a named business purpose, an owner, an expiry condition, and a revocation path. For NHIs and service accounts, teams should prefer short-lived credentials, federated workload identity, and just-in-time access over durable shared secrets. For human vendor users, periodic revalidation should confirm active contract scope, system necessity, and segregation from privileged functions. The 52 NHI Breaches Analysis shows how often identity misuse becomes the entry point once access persists longer than intended.

  • Review external accounts against contract scope, not just directory status.
  • Confirm federation trusts, OAuth grants, and API keys are still needed.
  • Revoke unused service accounts and rotate any secrets tied to third-party tooling.
  • Require asset owners to attest to access at a fixed cadence, especially for maintenance and ground operations.

In parallel, identity logs should be tested for vendor-specific anomalies such as unusual geolocation, atypical maintenance windows, or tool chaining that does not match the supplier’s normal workflow. These controls tend to break down in multi-operator airport environments because shared infrastructure, cross-company support desks, and emergency maintenance exceptions blur ownership and make timely revocation difficult.

Common Aviation Edge Cases and Where the Guidance Gets Hard

Tighter third-party controls often increase operational overhead, requiring organisations to balance resilience against turnaround speed, supplier access, and aircraft availability. That tradeoff is real in aviation, where delays are costly and emergency access is sometimes unavoidable.

Best practice is evolving, but current guidance suggests treating exceptions as time-boxed and observable rather than permanent. For example, a disrupted maintenance event may justify temporary elevated access, yet that access should expire automatically and be re-approved if the work continues. The same principle applies to airport integrators, baggage vendors, and software providers that support multiple carriers. If the access cannot be tied to a current need, it should not remain active.

There is also a hard boundary between organisational trust and technical trust. A vendor may still be contractually approved while a specific account, token, or integration is no longer appropriate. That is why reviews must cover roles, secrets, federation links, and machine-to-machine permissions together. The Ultimate Guide to NHIs is clear that weak offboarding and poor rotation remain common failure points, while OWASP Non-Human Identity Top 10 reinforces that standing access is the problem, not just credential quality.

In civil aviation, the guidance gets hardest when third-party access is embedded in safety-critical workflows, because revocation may be technically simple but operationally risky without a parallel fallback plan.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-05 Third-party access reviews reduce lingering non-human privileges and hidden trust paths.
CSA MAESTRO Agent and supplier trust chains need continuous governance and lifecycle control.
NIST AI RMF Risk governance should account for dynamic access drift in complex operational environments.
NIST CSF 2.0 PR.AC-4 Least privilege and access management directly address uncontrolled supplier access.
NIST SP 800-63 Federated identity assurance matters when suppliers authenticate across aviation systems.

Inventory third-party NHIs, then review and revoke any standing access that no longer maps to a current need.