EASA framework for cyber resilient aviation
Uninterrupted connectivity is a foremost consideration across the aviation industry where more digitised, data, AI, and ML- driven networks, with IT systems, cloud, and platforms require the highest cyber and information security. This is especially relevant between aircraft, helicopters and airlines and other operator’s Integrated Operations Control Centres (IOCCs), MROs, airports, and ATMs where information security is of the utmost importance.
Part-IS (Commission Implementing Regulation (EU) 2023/203 and Commission Delegated Regulation 2022/1645) is the latest EASA regulation to identify and manage information security (IS) risks with potential impact on Aviation Safety.
This regulation will provide a comprehensive framework for governance, risk and event management, continuous improvement, and reporting. This will enable the aviation ecosystem to mitigate and respond to cyber threats with the overall goal of collaboratively enhancing cyber resilience to secure Aviation Safety.
One big challenge will be the efficient and lean Safety Management System (SMS) and Civil Aviation Information Security Management System (ca-ISMS) integration into quality and business resilience management.
Want to know if you need to implement Part-IS?
Who needs to comply with Part-IS?
Aviation is in our DNA
For over three decades we have been working in cyber, information security, and safety.
Since the A380 / A350 programme, Airbus Protect has been engaged in aircraft safety & security assurance for Airbus contributing and shaping the building blocks of a sustainable and resilient security for safety risk management.
We have been part of shaping this standard
We have extensive experience in safety and cybersecurity auditing, governance and compliance as well as, risk management in aerospace and aviation. We further contribute to the enhancement of standards and risk mitigation in different internal and external working groups.
We know the gaps you have to close
Part-IS incorporates different cybersecurity standards / directives like NIST, ISO27k, NIS2 therefore some requirements of the new EASA framework like the establishment of an information security management system (ISMS) may sound familiar, however, this may not be the case as Part-IS introduces provisions that are specific to the context of Aviation Safety.
Beyond Compliance Risk Management