Skip to main content

OPM-11

· DOI Office of Aviation Services · 2025

Public domain · DOI Office of Aviation ServicesAviation Safety Documents

Overview

The OPM-11 () is a public-domain DOI Office of Aviation Services aviation safety document, republished here as a free chaptered HTML edition with a linked table of contents and the official PDF.

Publisher
DOI Office of Aviation Services
Document
Year
2025
Pages
34
Chapters
11

Key points

  • The DOI OPM-11 outlines the operational procedures for the use of Uncrewed Aircraft Systems (UAS) within the Department of the Interior.
  • UAS operations must comply with the 2024 National Defense Authorization Act (NDAA), which restricts procurement from adversarial entities.
  • All DOI UAS must be operated by certified remote pilots holding both a current FAA Part 107 certificate and a DOI remote pilot qualification card.
  • The use of personally owned UAS for DOI missions is prohibited, and all UAS must have an OAS-issued Aircraft Data Card or authorization letter.
  • Cooperators using UAS under DOI operational control must complete a self-assessment and obtain a Letter of Authorization from the Office of Aviation Services.
Frequently asked questions
What is the effective date of OPM-11?

The effective date of OPM-11 is January 1, 2026.

What are the requirements for vendors regarding NDAA compliance?

Vendors must certify NDAA compliance and provide documentation proving that their UAS systems do not contain restricted components or software as defined by the NDAA.

Can DOI employees operate UAS without a certification?

No, DOI employees are not authorized to manipulate the controls of DOI UAS unless they possess a current DOI Remote Pilot card or are receiving a flight evaluation from an approved pilot inspector.

What happens to non-compliant UAS systems?

Non-compliant UAS systems will be phased out and replaced with compliant systems, except for those used in wildland fire management and search and rescue operations.

What is required for cooperators to operate UAS under DOI control?

Cooperators must complete a DOI UAS Cooperator Programmatic Self-Assessment and obtain a Letter of Authorization from the Office of Aviation Services.

Appendix 1 – Page 1

OPM – 11 Appendix 1 – Page 1 Appendix 1 Definitions Operational Control: Per 14 CFR 1.1 Operational control, with respect to a flight, means the exercise of authority over initiating, conducting, or terminating a flight.

COA: Certificate of Authorization issued by the Air Traffic Organization to an operator for a specific UAS activity not covered under a Federal Aviation Regulation, such as 14 CFR Part 107.

MOA: A Memorandum of Agreement (MOA) is a written document describing a cooperative relationship between DOI and another party working together on a project or to meet an agreed upon objective. An MOA serves as a legal document and describes the terms and details of the partnership agreement.

NOTAM: A Notice To Airmen or NOTAM is a notice containing information (not known sufficiently in advance to publicize by other means) concerning the establishment, condition, or change in any component (facility, service, or procedure of, or hazard in the National Airspace System) the timely knowledge of which is essential to personnel concerned with flight operations.

TFR: A Temporary Flight Restriction (TFR) is a limitation on aviation activity applied to an area of airspace (defined both laterally and vertically) that has been temporarily or partially closed to non-participatory aircraft for a specified period due to a hazardous condition, a special event, or to provide a safe environment for operation of disaster relief aircraft. A NOTAM is issued containing information on the reason for the TFR, contact information and fine points of the restriction.

Appendix 2 – Page 1

OPM - 11 Appendix 2 – Page 1 Appendix 2 Guidance for End-Product Contracting (Aligned with the 2024 NDAA) End Product Contracts are not aircraft flight service contracts. They are used to procure specific outcomes (e.g., per-acre, per-unit, or per-head) rather than flight services. The intent is for contractors to provide all personnel and equipment necessary to achieve the specified service or deliverable. Contractors may use aircraft, including uncrewed aircraft systems (UAS), to meet performance objectives for activities such as animal capture, seeding, spraying, surveying, and photography. However, these contracts are procurement actions administered by bureau procurement units, not aviation flight services.

These contracts must adhere to OPM-35 and DOI procurement policies, ensuring that aviation management requirements under operational control do not apply if the contract meets the following criteria: • The operation aligns with the definition of “end-product” in OPM-35.

• It satisfies the provisions outlined in 353 DM 1.2A (3).

If these criteria are met, the aircraft operates under civil aviation regulations, and DOI aviation policies do not apply.

Contract Specifications for End-Product Contracts Specifications must focus on desired outcomes (e.g., service quantity/quality) and should not define aviation-specific standards. Bureau aviation managers must review contracts to ensure that specifications do not imply operational control over aircraft.

Acceptable Contract Language: 1. Aircraft and Pilot Requirements: Do not include language related to aircraft or pilot capabilities, standards, or payment provisions for flight hours.

2. Scope of Work: o Describe the area of work in terms of location, topography, elevation, slope, vegetation, and access.

o Include land-use restrictions for equipment as needed.

3. Compliance with Regulations: o "The contractor must comply with all applicable federal, state, and local regulations and permitting procedures."

4. Airspace Coordination: o If the project involves military airspace, state that the contractor is responsible for coordination with scheduling authorities (e.g., MOA, RA, MTR).

5. Equipment Requirements: o "The contractor must demonstrate that equipment will capture the data or imagery specified in the project."

Appendix 2 – Page 2

OPM - 11 Appendix 2 – Page 2 o Avoid referencing aircraft-specific equipment in these requirements.

6. Communication Systems: o "The contractor must provide a communication system that ensures seamless communication between project personnel and allows government inspectors to contact the contractor at any time."

7. Transportation: o "Only approved contractor personnel and equipment, along with any required government-provided equipment, may be transported by contractor vehicles, trailers, or animals."

8. Hazard Identification: o "Any hazards that could affect personnel or equipment must be identified and mitigated by the contractor before starting operations."

9. Aircraft Usage Reporting: o Do not include requirements for flight-hour reporting or aircraft usage logs.

Provisions for Covered UAS in Compliance with the 2024 NDAA Contracts must ensure that no covered UAS are used in performance of DOI missions unless exempted by the 2024 NDAA Funding Restrictions: o "Department contracts, grants, and agreements shall not allocate funds for the use of covered UAS."

2. Operational Restrictions: o "Covered UAS shall not be operated on Department-managed lands."

A "covered UAS" is defined as any UAS that: • Is manufactured by an entity domiciled in an adversary country.

• Contains critical electronic components (e.g., flight controllers, radios, cameras) made by an entity in an adversary country.

• Uses operating software developed by an entity in an adversary country.

• Relies on network connectivity or data storage administered by an adversary country.

• Transmits data or imagery through components manufactured by such entities.

Operational Control and Reporting Requirements DOI will not exercise operational control over contractor aircraft. Contract personnel must follow civil aviation regulations (14 CFR) independently of DOI aviation oversight.

• DOI personnel will not direct flight profiles or operational details such as takeoff, landing, or fueling procedures.

• Any DOI involvement will focus on ground operations, such as setting scale bars or collecting data for ground-truthing.

Appendix 2 – Page 3

OPM - 11 Appendix 2 – Page 3 Aircraft Incident Reporting: Although contractor aircraft operate under civil aviation regulations, the Bureau will report aviation mishaps through FAA channels to promote safety. These incidents should be noted in the Contract Daily Diary and reported following standard procedures for End Product contracts.

Reconnaissance and Observation Flights If Bureau employees need to conduct aerial surveys related to the contract, separate flight service procurements through AQD are required. These flights must adhere to DOI aviation management policies, including: • Current OAS-approved pilots and aircraft.

• DOI contracts or Aircraft Rental Agreements.

Military Airspace Operations If a project involves military airspace, the contractor must coordinate with military scheduling offices. While DOI personnel may inform military authorities of the project timeframe, it is the contractor’s responsibility to manage the coordination.

Summary End Product contracts ensure contractors deliver specified outcomes without aviation-specific oversight by DOI. Adhering to the 2024 NDAA and related policies ensures compliance, particularly regarding the use of covered UAS. Bureau personnel must focus on procurement oversight, not operational control of contractor aircraft, to maintain clear boundaries between End Product and flight service contracts.

Appendix 3

OPM - 11 Appendix 3 A ppendix 3 - Page 1 CYBERSECURITY BEST PRACTICES FOR O RCIAL UNMANNED AIRCRAFT SYSTEMS PERATING COMME

CYBERSECURITY BEST PRACTICES FOR OPERATING

COMMERCIAL UNMANNED AIRCRAFT SYSTEMS (UAS S )

UASs provide innovative solutions for tasks that are dangerous, time consuming, and costly. Critical infrastructure operators, law enforcement, and all levels of government are increasingly incorporating UASs into their operational functions and will likely continue to do so. Although UASs offer benefits to their operators, they can also pose cybersecurity risks, and operators should exercise caution when using them.

To help UAS users protect their networks, information, and personnel, the Department of Homeland Security (DHS)/Cybersecurity and Infrastructure Security Agency (CISA) identified cybersecurity best practices for UASs. This product, a companion piece to CISA’s Foreign Manufactured UASs Industry Alert, can assist in standing up a new UAS program or securing an existing UAS program, and is intended for information technology managers and personnel involved in UAS operations. Similar to other cybersecurity guidelines and best practices, the identified best practices can aid critical infrastructure operators to lower the cybersecurity risks associated with the use of UAS, but do not eliminate all risk.

INSTALLATION AND USE OF UAS SOFTWARE AND FIRMWARE

An important part of managing risk when employing UASs is to understand the steps involved and potential vulnerabilities introduced during the installation and use of UAS software and firmware. UAS operators should strongly consider and evaluate the following cybersecurity best practices when dealing with software and firmware associated with UAS:  Ensure that the devices used for the download and installation of UAS software and firmware do not access the enterprise network.

 Properly verify and securely conduct all interactions with UAS vendor and third-party websites. Take extra precaution to download software from properly authenticated and secured websites and ensure app store hosts verify mobile applications.

o Access these websites or app stores from a computer not associated with, or at least not connected to, the enterprise network or architecture.

o Ensure the management of security for mobile devices that will be directly or wirelessly connected to the 1 2,3 UAS. 0 F Review additional information for enhancing security on mobile devices. 1 F 2 F For more information, see: National Institute of Standards and Technology (NIST). (2013). “Guidelines for Managing the Security of Mobile Devices in the Enterprise.” https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-124r1.pdf . Accessed May 16, 2019.

For mobile security guidance from Apple, visit www.apple.com/privacy/manage-your-privacy .

For mobile security guidance from Android, visit www.android.com/play-protect .

CONNECT WITH US Linkedin.com/company/ cisagov www.cisa.gov @CISAgov | @cyber | @uscert_gov For more information, email Central@cisa.gov Facebook.com/CISA

Appendix 3 - Page 2

OPM - 11 Appendix 3 - Page 2 CYBERSECURITY BEST PRACTICES FOR OPERATING COMMERCIAL UNMANNED AIRCRAFT SYSTEMS (UASs)  Ensure file integrity monitoring processes are in place before downloading or installing files. Check to see if individual downloads or installation files have a hash value or checksum. 3 F After downloading an installation file, compare the hash value or checksum of the installation file against the value listed on the vendor’s download page to ensure they match.

 Run all downloaded files through an up-to-date antivirus platform before installation and ensure the platform remains enabled throughout installation.

 Verify a firewall on the computer or mobile device is enabled to check for potentially malicious inbound and outbound traffic caused by the recently installed software. External network communications could be part of the installation process and could potentially expose your system to unknown data privacy risks.

 During installation, do not follow “default” install options. Instead, go through each screen manually and consider installing software on a removable device (external HDD or USB drive).

o Deselect any additional features or freeware bundled into the default install package.

o Disable automatic software updates. Necessary updates should follow the same process outlined for download and installation.

o Thoroughly review any license agreements prior to approval. Consider involving a legal team in the process to ensure organizations do not unknowingly agree to unsafe or hazardous practices on the part of the vendor.

SECURING UAS OPERATIONS

An important part of operating UASs is to ensure that communications are secure during all aspects of usage. There are multiple publicly accessible sites that indicate and detail how to intercept UAS communications and hijack UASs during flight operations. UAS operators should consider and evaluate the following cybersecurity best practices when conducting UAS operations:  If a UAS data link is through Wi-Fi connections between the UAS and the controller. 4 F o Ensure the data link supports an encryption algorithm for securing Wi-Fi communications.

 Use WPA2-AES security standards or the most secure encryption standards available.

 Use highly complicated encryption keys that are changed on a frequent basis. Ensure that encryption keys are not easily guessable, and do not identify the make or model of the UAS or the operating organization.

o Use complicated Service Set Identifiers (SSIDs) that do not identify UAS operations on the network. Avoid using the specific make or model of the UAS or the operating organization in the SSID.

o Set the UAS to not broadcast the SSID or network name of the connection.

o Change encryption keys in a secure location to avoid eavesdropping either visually or from wireless monitoring.

 If the UAS supports the Transport Layer Security (TLS) protocol, ensure that it is enabled to the highest standard that the UAS supports.

A checksum is a value derived from a segment of computer data calculated before and after transmission to assure data is free from tampering and errors. A hash value is a fixed-length numeric value that results from the calculation of a hashing algorithm. A hash value uniquely identifies data and is often used for verifying data integrity.

For more information on securing a wireless network, see: DHS Cybersecurity Engineering. (2017). “A Guide to Securing Networks for Wi-Fi (IEEE 802.11 Family).” www.us-cert.gov/sites/default/files/publications/A_Guide_to_Securing_Networks_for_Wi-Fi.pdf . Accessed March 18, 2019.

CONNECT WITH US Linkedin.com/company/ cisagov www.cisa.gov @CISAgov | @cyber | @uscert_gov For more information, email Central@cisa.gov Facebook.com/CISA

Appendix 3 - Page 3

OPM - 11 Appendix 3 - Page 3 CYBERSECURITY BEST PRACTICES FOR OPERATING COMMERCIAL UNMANNED AIRCRAFT SYSTEMS (UASs)  Have the data links for UAS control, telemetry, payload transmission, video transmission, and audio transmission encrypted with different keys. Make sure the UAS is able to encrypt the data stored onboard.

 Use standalone UAS-associated mobile devices with no external connections or disable all connections between the Internet and the UAS and UAS-associated mobile devices during operations. Consider running wireless traffic analyzers during selected UAS operations to understand and monitor UAS communications traffic while in use.

 Run mobile device applications in a secure virtual sand-box configuration that allows operation while securely protecting the device and the operating system.

DATA STORAGE AND TRANSFER

Ensuring the security and privacy of UAS data, while at rest or in transit, is essential to managing UAS cybersecurity risks.

UAS operators should consider and evaluate the following cybersecurity best practices for UAS data storage and transfer:  When connecting the UAS or UAS-associated removable storage device to a computer: o Use a standalone computer to connect to the UAS or removable storage device to ensure no access to the Internet or enterprise network.

o Verify a firewall on the computer or mobile device is enabled to check for potentially malicious inbound and outbound traffic caused from the connection of the UAS or removable storage device. Verify and ensure that the computer has up-to-date antivirus installed.

 Data should be encrypted both at rest and in transit to ensure confidentiality and integrity. 5 F  Authentication mechanisms should be in place for UASs with access to private or confidential data. Use Multi- Factor Authentication (MFA) whenever possible for accounts associated with UAS operations. 6 F  Follow data management policies for data at rest, data in transit, and any sensitive data.

 Erase all data from the UAS and any removable storage devices after each use.

INFORMATION SHARING AND VULNERABILITY REPORTING

By participating in information-sharing programs and reporting non-public, newly-identified vulnerabilities, users will have access to timely information to mitigate cybersecurity threats. These programs can also serve as a forum for UAS operators to share security vulnerabilities that could potentially impact the Nation’s critical infrastructure or pose a threat to public health and safety. The following are three information sharing programs:  Cyber Information Sharing and Collaboration Program (CISCP): o CISCP enables actionable, relevant, and timely information exchange through trusted, public-private partnerships across all critical infrastructure (CI) sectors by leveraging the depth and breadth of DHS cybersecurity capabilities within a focused, operational context.

For more information on encrypting stored data, see: National Institute of Standards and Technology (NIST). (2007). “Guide to Storage Encryption Technologies for End User Devices.” NIST Special Publication 800-111. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800 - 111.pdf . Accessed March 15, 2019.

For more information on security controls, see: National Institute of Standards and Technology (NIST). (2013). “Security and Privacy Controls for Federal Information Systems and Organizations.” NIST Special Publication 800-53, Revision 4.

https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-53r4.pdf . Accessed March 15, 2019.

CONNECT WITH US Linkedin.com/company/ cisagov www.cisa.gov @CISAgov | @cyber | @uscert_gov For more information, email Central@cisa.gov Facebook.com/CISA

Appendix 3 - Page 4

OPM - 11 Appendix 3 - Page 4 CYBERSECURITY BEST PRACTICES FOR OPERATING COMMERCIAL UNMANNED AIRCRAFT SYSTEMS (U o For more information on the CISCP program, visit www.dhs.gov/ciscp or email CISCP_Coordination@hq.dhs.gov .

 Automated Indicator Sharing (AIS) Program: o The AIS program enables the quick exchange of cyber threat indicators between the Federal Government and the private sector through CISA. Companies that share indicators through AIS are granted liability protection and other protections through the Cybersecurity Information Sharing Act of 2015.

o For more information on CISA services, call 1-888-282-0870 or email Central@cisa.gov . For more information on AIS and how to join, go to www.cisa.gov/automated-indicator-sharing-ais .

 Information Sharing and Analysis Centers (ISACs): o Information Sharing and Analysis Centers (ISACs) are non-profit, member-driven organizations formed by critical infrastructure owners and operators to share information between government and industry. CISA, through the NCCIC, works in close coordination with all of the ISACs.

o For more information about ISACs, go to www.nationalisacs.org/ .

If an organization discovers a UAS software or hardware vulnerability, or a suspicious or confirmed UAS cybersecurity incident occurs, CISA recommends reporting the vulnerability or incident through the following channels:  DHS CISA: o Email Central@cisa.dhs.gov or call 1-888-282-0870. When sending sensitive information to DHS CISA via email, we recommend encryption of messages. For more information, visit us-cert.cisa.gov/report .

 CERT Coordination Center: o To report a vulnerability, go to www.kb.cert.org/vuls/report .

The UAS Cybersecurity Best Practices document is a collaborative product written by CISA's National Risk Management Center and Cybersecurity Division. This product was coordinated with the DHS/CISA/Infrastructure Security Division, DHS/Federal Protective Service, U.S. Army/Combat Capabilities Development Command, and Federal Bureau of Investigation/Cyber Division.

The National Risk Management Center (NRMC), Cybersecurity and Infrastructure Security Agency (CISA), is the planning, analysis, and collaboration center working in close coordination with the critical infrastructure community to Identify; Analyze; Prioritize; and Manage the most strategic risks to National Critical Functions. These are the functions of government and the private sector so vital to the United States that their disruption, corruption, or dysfunction would have a debilitating impact on security, national economic security, national public health or safety, or any combination thereof.

NRMC products are visible to authorized users at HSIN-CI and Intelink. For more information, contact NRMC@hq.dhs.gov or visit www.cisa.gov/national-risk-management .

June 11, 2019 CONNECT WITH US Linkedin.com/company/ cisagov www.cisa.gov @CISAgov | @cyber | @uscert_gov For more information, email Central@cisa.gov Facebook.com/CISA

Appendix 4 – Page 1

OPM - 11 Appendix 4 – Page 1 Appendix 4 Useful Web Links DOI UAS Website ( Link to public DOI Website ) DOI’s Interagency UAS Site (access permission required) Link to the Interagency UAS SharePoint.

DOI Small UAS Annual Inspection Form Link to Small UAS Inspection Form DOI Small Uncrewed Aircraft Systems Acquisition Request Form (OAS-13U) Link to OAS- 13U Form DOI FAA MOA for Class G operations https://www.doi.gov/sites/doi.gov/files/uploads/DOI_FAA_MOA_Class_G_0911201 5.pdf DOI/FAA MOA for BVLOS flights within TFRs https://www.doi.gov/sites/doi.gov/files/uploads/FAA_DOI_UAS_TFR_MOA_8-13- 15.pdf DOI Blanket COA Link to Certificate of Waiver or Authorization between FAA and DOI (6 Sept. 2018; current).

Presidential Memo for Protecting Privacy, Civil Rights and Civil Liberties Link to 2015 "Presidential Memo".

DOI UAS Privacy Impact Assessment Link to DOI UAS Privacy Impact Assessment Online NOTAM filing service 1800wxbrief.com https://www.1800wxbrief.com/ Sky Vector flight planning tools https://skyvector.com/ Interagency Fire UAS Operations Guide https://www.nwcg.gov/sites/default/files/publications/pms515.pdf

Appendix 5 – Page 1

OPM - 11 Appendix 5 – Page 1 Appendix 5 DOI Best Practices for Physical Security of Uncrewed Aircraft Systems (UAS) Introduction Uncrewed Aircraft Systems (UAS) provide innovative solutions for tasks that are hazardous, time-consuming, or costly. As UAS usage expands within DOI, it is essential to mitigate security risks that accompany these assets. This guide outlines best practices to protect UAS and associated equipment against theft, damage, or misuse. These recommendations should be adopted across DOI agencies to enhance operational security.

While these measures reduce the likelihood of loss, they do not eliminate risk. Managers, operators, and staff must remain vigilant and adapt these practices to fit their operational environments.

General Security Risk Assessment Considerations Evaluate the security risks associated with UAS storage and transportation using the following questions: Risk Level Mitigation Consideration (High/Medium/Low) Measures Is access to the property controlled by ID checkpoints?

Is the area monitored by CCTV or security cameras?

Does the building/area have sufficient security lighting?

Are security personnel present or performing rounds?

Are all accessible doors locked and secured?

Is UAS equipment stored behind two levels of security?

Answering “Yes” to these questions typically indicates a reduced risk of theft or misuse.

Agencies should adapt mitigation measures as needed to address any vulnerabilities identified in the assessment.

Storage and Transportation Guidelines 1. Federal Facilities • Access Controls: Require identification badges or visitor sign-in for entry.

• Best Practice: Store UAS in locked offices or storage areas behind multiple layers of security (e.g., locked room and secured case).

2. Leased or Partnered Facilities • Access Controls: Follow the security protocols of the hosting facility.

Appendix 5 – Page 2

OPM - 11 Appendix 5 – Page 2 • Best Practice: Secure UAS in a locked room with additional physical locks on cases or racks.

3. University or Affiliate Locations • Security Measures: Comply with the affiliate’s security protocols, including ID-based access and camera surveillance.

• Best Practice: Limit the number of personnel with access to UAS equipment to maintain accountability.

4. Hotel or Temporary Lodging • Security Measures: Use in-room safes or locks for UAS storage.

• Best Practice: Place a "Do Not Disturb" sign on the door when away and ensure the UAS case is locked.

5. Residences • Security Measures: Keep UAS equipment inside the dwelling, not in garages or vehicles.

• Best Practice: Use home security systems, if available, and avoid storing UAS in unattended vehicles.

6. Vehicles • Security Measures: Lock all doors and enable anti-theft mechanisms.

• Best Practice: Avoid leaving UAS unattended in vehicles; if unavoidable, park in well- lit areas and conceal equipment.

7. Campsites or Remote Locations • Security Measures: Adapt security practices to the environment (e.g., lock UAS inside tents or cabins).

• Best Practice: Assign someone to remain with the equipment whenever possible to maintain security.

Source & rights

Source: doi.gov. Public-domain U.S. Government work (17 USC §105) — freely reproducible.

Permanent URL — we don’t break links.

Report a problem or request removal

Document details

Doc number
Publisher
DOI Office of Aviation Services
Year
2025
Pages
34
File size
876 KB
Chapters
11