lagen.nu
AMC & GM to Part-IS.D.OR — Issue 1, Amendment 1

AMC & GM to Part-IS.D.OR — Issue 1, Amendment 1

Utgivare
Europeiska unionens byrå för luftfartssäkerhet
Antagen
2025-07-24
Utfärdat genom
ED Decision 2025/014/R
Språk
engelska
Ämnesord
Part-IS.D.OR - Information Security – Organisation Requirements (Delegated Regulation (EU) 2022/1645)
Källa
www.easa.europa.eu
Endast på engelskaEuropeiska unionens byrå för luftfartssäkerhet har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens byrå för luftfartssäkerhet.

This document shows deleted, new or amended text as follows: — deleted text is struck through; — new or amended text is highlighted in blue; — an ellipsis ‘[…]’ indicates that the rest of the text is unchanged.

N o te to t h e r e a d e r

In amended, and in particular in existing (that is, unchanged) text, ‘Agency’ is used interchangeably with ‘EASA’. The interchangeable use of these two terms is more apparent in the consolidated versions. Therefore, please note that both terms refer to the ‘European Union Aviation Safety Agency (EASA)’.

Annex I to ED Decision 2025/014/R Page 1 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

GM1 IS.D.OR.200 Information security management system (ISMS)

An information security management system (ISMS) is a systematic approach to establish, implement, operate, monitor, review, maintain and continuously improve the state of information security of an organisation. Its objective is to protect the information assets, such that the operational and safety objectives of an organisation can be reached in a risk-aware, effective and efficient manner. Generally speaking, an ISMS establishes an information security risk management process, based upon the results of information security impact analyses, which basically determine its scope. If information security breaches may cause or contribute to aviation safety consequences, information security requirements need to limit the their impact or influence of information security breaches on levels of aviation safety, which are deemed acceptable. Hence, all roles, processes, or information systems, which may cause or contribute to aviation safety consequences, are within the scope of Regulation (EU) 2023/203. The ISMS provides for means to decide on needed information security controls for all architectural layers (governance, business, application, technology, data) and domains (organisational, human, physical, technical). It further allows to manage the selection, implementation, and operation of information security controls. Finally, it allows to manage the governance, risk management and compliance (GRC) within the ISMS scope. The overall risk assessment considers safety consequences influenced by information security risks. These may emerge as threats, hazards, escalation factors that weaken barriers, or direct triggers of existing hazards. When conducting this assessment, both aspects, information security and safety need to be coordinated throughout the process. This ensures mutual understanding of the objectives and the implementation of preventive measures against all types of threats or weaknesses, as well as mitigating measures. The risk management process is thus based on aviation safety risk assessments and derived information security risk acceptance levels, which are designed to effectively treat and manage information security risks with a potential impact on aviation safety caused by threats exploiting vulnerabilities of information assets in aeronautical systems. Interacting bow-ties is one possible way that allows for a higher-level and non-exhaustive illustration of how different disciplines of risk assessment may need to collaborate to establish a common risk perspective, as depicted in Figure 1. The below Figure 1 from ICAO Doc 10204 ‘Manual on Aviation Information Security’ illustrates these interactions.

Annex I to ED Decision 2025/014/R Page 2 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Risk Treatment

Risk Assessment

Safety Assessment

Information security Assessment

Y

N

Risk Treatment

Figure 1: Bow-tie representation of management of aviation safety risks posed by information security threats

Annex I to ED Decision 2025/014/R Page 3 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

In the drawing, the term ‘context’ in the communication between the safety assessment process (SAP) and the information security assessment process (ISAP) carries slightly different notions, which need to be understood and distinguished. In order to satisfy the safety requirements, the SAP will provide context information such as: — the architecture of the systems and the functional descriptions of the elements within the scope, including those related to the barriers. Systems should be understood as the dynamic interaction between people, processes, and products or services; — all identified relevant safety hazards; — the top events and their relations (e.g. triggers) to those hazards. In addition to context information, it provides the target likelihood of the related information security successful compromise. This target likelihood is commensurate with the safety objectives related to the severity of the safety consequence. However, it needs to be complemented to include information about the acceptable level of uncertainty, in order to be able to rely adequately on the results of the ISAP. In turn, the ISAP will return context information such as: — modification to the architecture of the systems and functional descriptions of the elements modified or added, whether those were safety barriers or other items; — additional threats; — potentially additional safety hazards; — additional direct triggers of hazards; — additional escalating factors affecting barriers. In addition to context information, it provides the achieved likelihood of an information security successful compromise. While this likelihood is consistent with the safety objectives set by the SAP, the achieved level of uncertainty also needs to be considered. The interaction between SAP and ISAP is iterative and continues until the safety risk is acceptable, i.e. the target likelihood of the related information security successful compromise has been achieved. The interaction can start from safety consequences identified through the SAP that fall within the scope of the ISMS risk analysis, or from existing information security assessments. The ISMS in this Regulation should bring together the information security and aviation safety competencies in most of the processes, including, for instance, identifying critical systems or threats, and assessing potential impacts on and risks to aviation safety. ISMS implementation and maintenance [...] PART-IS versus ISO/IEC 27001:2022 cross reference table For a mapping between the Part-IS provisions main tasks required under Pat-IS and the clauses and associated controls in ISO/IEC 27001:2022, refer to Appendix II IV.

Annex I to ED Decision 2025/014/R Page 4 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

GM1 IS.D.OR.200(d) Information security management system (ISMS)

PROPORTIONALITY IN ISMS IMPLEMENTATION

When implementing the processes and procedures, as well as establishing the roles and responsibilities required under point IS.D.OR.200(d), the organisation should primarily consider the risks that it may be posing to other organisations, as well as its own risk exposure. Other aspects that may be relevant include the organisation’s needs and objectives, information security requirements, its own processes and the size, complexity and structure of the organisation, all of which may change over time. As a general guide, the following aspects of the degree of safety relevance and organisational complexity could be taken into account when defining the ISMS. Each of these influences the implementation of the ISMS in certain areas: (a) The organisation’s position in the functional chain and the number and degree of safety relevance of the interfacing organisations/stakeholders. (b) The complexity of the organisational structure and hierarchies (e.g. number of staff, departments, hierarchical layers, external location, subsidiaries, etc.) (c) The complexity of the information and communication technology systems and data used by the organisation and their connection to external parties. More details on the influence on the proportionate implementation of Part-IS for each aspect of safety relevance and organisational complexity are provided in Appendix V.

SUPPORTED IMPLEMENTATION OF THE ISMS

[...]

GM1 IS.D.OR.200(e) Information security management system (ISMS)

Any organisation that believes that it does not pose any information security risk with a potential impact on aviation safety, either to itself or to other organisations, may consider requesting an approval for a derogation by the competent authority following the procedure outlined in AMC1 IS.D.OR.200(e). Existing safety risk assessments, such as those carried out as part of the SMS, can form the basis of enhanced assessments considering safety risks arising from information security threats. It should be noted that applications for partial exemption from individual articles are not possible.

APPLICATION FOR A DEROGATION

In order to ensure a consistent approach by organisations when submitting a derogation request, the competent authority may establish an official derogation request application form.

Annex I to ED Decision 2025/014/R Page 5 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

The application for a derogation, based on the application form where one exists or in a format decided by the organisation, will need to be signed by the accountable manager of the applicant organisation and submitted to the appropriate competent authority for review and consideration. The application for a derogation should contain preliminary information used for a pre-assessment by the competent authority, including: — Company information and contact information; — Affected approval(s); — Detailed justification for the exclusion of the provisions; — Overview of services that the organisation provides and receives; — Architecture overview of information systems used for business operation; — Summary of the high-level information security risk assessment aligned with the above architecture; — Methodology used to perform the information security risk assessment; — List of people and roles involved in the information security risk assessment process; — Date and signature. Note: At this stage, the high-level risk assessment needs to properly document the absence of information security risks that may impact safety. To do so, it should at least cover the identification of the scope and boundaries, as required under points IS.D.OR.205 (a) and (b), and the analysis of safety impact, as required under point IS.D.OR.205(c).

EVALUATION OF THE REQUEST FOR A DEROGATION

The competent authority reviews the information security risk assessment and other supporting documentation, normally assessing whether: — the documentation is sufficient for a proper analysis and assessment; — the repository or asset inventory of digital systems, data flows and processes is comprehensive; — the high-level information security risk assessment has been conducted in accordance with the organisation’s methodology and with the appropriate diligence; — the relevant stakeholders have been involved in the assessment process; — the assessment has been performed by people with sufficient expertise in information security and aviation safety; — the organisation has assigned and indicated a point of contact for enquiries. Figure 1 below depicts the process, including the pre-assessment. If the pre-assessment provides the competent authority with sufficient evidence that the derogation request is legitimate and that the organisation meets the expected criteria, the process will proceed to the exchange of more detailed information.

Annex I to ED Decision 2025/014/R Page 6 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Organisation Competent Authority

Figure 1: Representation of the derogation process Note 1 to Figure 1: The objective of this step is to obtain preliminary information about the organisation risk profile by using suitable means (e.g. questionnaire, self-assessment template, request tool, etc.) Note 2 to Figure 1: The objective of this step is to conduct a pre-evaluation to check whether the organisation has the possibility to be granted a derogation. The pre-assessment allows to avoid a detailed assessment if the prerequisites for a derogation are not met.

Annex I to ED Decision 2025/014/R Page 7 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

EXPECTATIONS AND RECOMMENDATION AFTER DEROGATION APPROVAL

Once a derogation approval has been granted, the organisation is expected to undertake the following on a continuous basis: — Comply with all provisions of the regulation which are not exempted, in particular point IS.D.OR.200(a)(13) which should not be limited to only protection of the received information. When transmitting information with confidential nature, the organisation needs to have secure means in place as well; — Comply with Regulation (EU) No 376/2014 to take into account the obligation to comply with the reporting requirements. — Monitor any changes in the organisation’s scope of work and identify those which may have a potential impact on the documented information, which supports the derogation approval. Where such changes are identified, the organisation should ensure that they are brought to the attention of the competent authority without delay and notified in accordance with the applicable implementing rule. — Monitor the risk picture for any variation due to changes in the safety and security environment over time. To this end, point IS.D.OR.205(d) should be considered. — Ensure that the accountable manager or the head of the design of the organisation can demonstrate an understanding of the derogation process and the terms on which the approval has been granted. This means that at least one person in the organisation needs to have a basic understanding of the Regulation. To this end, point IS.D.OR.240(a)(3) and the related AMC and GM should be considered. — Implement basic protection against information security risks according to industry best practices. — Remain up to date with the latest information security threat landscape and consult the respective national authority for additional guidance.

EXAMPLES

[...]

GM1 IS.D.OR.210 Information security risk treatment

Unacceptable risks identified in accordance with point IS.D.OR.205 require a risk treatment process that may lead to the introduction of information security measures, often referred to as information security controls. For each identified risk, the organisation should defines the specific risk treatment measures, methods or resources that will be used over the life cycle of each asset to: — manage risk reduction; — monitor and maintain each asset;

Annex I to ED Decision 2025/014/R Page 8 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

— update and fulfil activities for configuration management; — manage supply chain; — manage contracted services or service provider. The review of risk treatment measures should include includes life cycle considerations which are introduced by equipment, procedures and personnel. A risk treatment plan as an outcome of the risk management process should include includes a prioritisation of risks, the corresponding information on the objectives and means for risk treatment to reach an acceptable level of risk, as well as agreed timelines specifying when responsible personnel should have implemented the risk treatment measures. The timelines for the implementation of a risk treatment measure should be agreed are subject to agreement by the personnel responsible for the implementation and should be are communicated to and accepted by the accountable manager by the accountable manager or, in the case of design organisations, by the head of the design organisation, of the organisation or delegated person(s). Any subsequent implementation delay, together with its cause, reason, rationale or necessity, should be is documented in the risk treatment plan, for risks that may lead to an unsafe condition. The updated risk treatment should be communicated to the competent authority in case the materialisation of risk would lead to an unsafe condition. The delay is also subject to the acceptance by the accountable manager of the organisation, or by the head of the design organisation, or delegated person(s). This person may condition such acceptance on the implementation or availability of compensating controls or reactive measures to monitor, early detect and timely respond to the materialisation of the risk in treatment. In order to timely respond, the incident response team may be informed to trigger their preparedness. […]

GM1 IS.D.OR.240(g) Personnel requirements

NECESSARY COMPETENCE AND TRAINING PROGRAMME

A training programme should start with the identification of the competence required by the personnel for each role, followed by the identification of the gaps between the existing competence and the required one. In order to develop the list of competencies, an organisation may use, as initial guidance, an existing cybersecurity competence framework such as the European e-Competence Framework (e-CF) or the NICE (National Initiative for Cybersecurity Education) based on the NIST Cybersecurity Framework (NIST CSF). In Appendix II, the main tasks of this Regulation are listed and mapped to the competencies derived from the EU e-CF or, for ease of mapping, to the functions and categories of the NIST CSF. This mapping may be used to establish a baseline to identify the aforementioned competence gaps. However, it should be noticed that existing cybersecurity/information security competence frameworks such as the NICE typically focus primarily on the protection of standard information technologies; therefore, the proposed list of competencies may need to be adapted to the technologies or integrated with processes used in the organisation.

Annex I to ED Decision 2025/014/R Page 9 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

The bridging of the identified gaps should be seen as the objective of the training programme, which should further include the scope, content, methods of delivery (e.g. classroom training, e-learning, notifications, on-the-job training) and frequency of training that best meet the organisation’s needs considering the size, scope, required competencies, and complexity of the organisation. Finally, as information security/cybersecurity evolves due to the rise of new threats, the organisation should periodically review the adequacy of the training programme. ROLE-BASED COMPETENCE FRAMEWORK Although under this Regulation there are no provisions for specific roles, besides the optional nomination of a CRP, for organisations characterised by a large number of staff members and hierarchical layers it may be convenient to identify some roles and the related required competencies. To this end EASA, has developed an adaptation of the European Cybersecurity Skills Framework (ECSF) published by ENISA in September 2022 that can be found in the Appendix VI.

GM1 IS.D.OR.260 Continuous improvement

[…] Similar provisions for continuous improvement are provided for in other information management systems such as ISO/IEC 27001 (see Appendix IIIV to this document). […]

Appendix II — Main tasks stemming from the implementation of Part-IS, including mapping mapped to the EU e-CF and the NIST CSF 1.1 2.0 competencies and ISO/IEC 27001 clauses and controls

Activity type Reference EU e-CF NIST CSF 2.0 Part-IS main task Management, Part-IS Operational Competence Functions & areas & skills categories Establish and operate an ISM (E.08) GV.OP – IS information security Management IS.D.OR.200(a) Governance management system (ISMS) Establish the scope of the ISMS in ISM (E.08) GV.RM – Risk accordance with according to Management IS.D.OR.205(a) Management Part-IS requirements Implement and maintain an ISM (E.08) GV.OP – IS Management information security policy IS.D.OR.200(a)(1) Governance ISM (E.08), Risk Identify and review information IS.D.OR.200(a)(2) ID.RA – Risk Management Management security risks IS.D.OR.205 Assessment (E.02) ISM (E.08), Risk Implement information security IS.D.OR.200(a)(3) PR.IP – Management Management risk treatment measures IS.D.OR.210 Information (E.02)

Annex I to ED Decision 2025/014/R Page 10 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference EU e-CF NIST CSF 2.0 Part-IS main task Management, Part-IS Operational Competence Functions & areas & skills categories Protection Processes Implement measures to detect Incident DE.AE – information security events and IS.D.OR.200(a)(5) Management Management Anomalies and identify those related to aviation IS.D.OR.220 (C.04) Events safety Implement measures that have been notified by the competent Operational IS.D.OR.200(a)(6) authority Take appropriate remedial actions to address findings IS.D.OR.200(a)(7) Both notified by the competent IS.D.OR.225 authority (non-compliances) Implement an external Incident RS.CO – IS.D.OR.200(a)(8) information security reporting Management Management Communicatio IS.D.OR.230 scheme (C.04) ns Monitor compliance with this Compliance GV.RM – Risk Regulation and report findings to Operational IS.D.OR.200(a)(12) (E.09) Management top management Information Protect confidentiality of Security PR.DS – Data Operational IS.D.OR.200(a)(13) exchanged information Management Security (E.08) Implement and maintain a Information GV.IA – continuous improvement process IS.D.OR.200(b) Security Improvement to measure the effectiveness and Management IS.D.OR.260 Management and maturity of the ISMS and strive to (E.08) Assessment improve it GV.IA – Document and maintain all key ISM (E.08), Improvement processes, procedures, roles and Management IS.D.OR.200(c) Compliance and responsibilities (E.09) Assessment Identify all elements which could Risk ID.AM – Asset be exposed to information Management IS.D.OR.205(a) Management Management security risks (E.02) Identify the interfaces with other Risk ID.BE – organisations which could result Management Management IS.D.OR.205(b) Business in exposure to information (E.02), Business Environment security risks Change

Annex I to ED Decision 2025/014/R Page 11 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference EU e-CF NIST CSF 2.0 Part-IS main task Management, Part-IS Operational Competence Functions & areas & skills categories Management (E.07) Risk Identify information security risks ID.RA – Risk Management IS.D.OR.205(c) Management and assign a risk level Assessment (E.02) Review and update the risk Risk GV.RM – Risk assessment based on certain Operational IS.D.OR.205(d) Management Management criteria (E.02) Develop and implement Risk GV.RM – Risk measures to address risks and Operational IS.D.OR.210(a) Management Management verify their effectiveness (E.02) Risk Communicate the outcome of the RS.CO – Management risk assessment to management, Communicatio Operational IS.D.OR.210(b) (E.02), ISM other personnel and other ns (E.08) organisations sharing an interface Establish an internal information DE.CM – security reporting scheme to IS.D.OR.200(a)(4) Incident Security enable the collection and Management IS.D.OR.215(a) Management Continuous evaluation of information IS.D.OR.215(e) (C.04) Monitoring security events from personnel Supplier DE.CM – Ensure that contracted Relationship Security organisations report information Management IS.D.OR.215(c) Management Continuous security events (E.10) Monitoring Analyse internally reported Incident DE.AE – occurrences to identify IS.D.OR.215(b)(1)- Operational Management Anomalies and information security events, (b)(3) (C.04) Events incidents, and vulnerabilities Implement measures to detect in DE.CM – processes and operations Security ISM (E.08) information security events Operational IS.D.OR.220(a) Continuous which may have a potential Monitoring impact on aviation safety

Annex I to ED Decision 2025/014/R Page 12 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference EU e-CF NIST CSF 2.0 Part-IS main task Management, Part-IS Operational Competence Functions & areas & skills categories Implement measures to respond Incident RS.RP – to information security events Operational IS.D.OR.220(b) Management Response that may cause an information (C.04) Planning security incident Incident Cooperate on investigations with Management other organisations that (C.04), Legal RS.AN – Management IS.D.OR.215(d) contribute to the information Advice and Analysis security of its own activities Compliance (E.09) Implement measures to recover Incident RC.RP – from information security Operational IS.D.OR.220(c) Management Recovery incidents (C.04) Planning Manage risks associated with Supplier contracted activities with regard Relationship GV.RM – Risk Management IS.D.OR.235 to the management of Management Management information security (E.10) Create and maintain a process to GV.PO – ensure that there is sufficient Personnel Strategy, personnel to perform all activities Management IS.D.OR.240(f) Development Policy, and regarding information security (D.11) Oversight management Create and maintain a process to GV.PO – Personnel ensure that the personnel have Strategy, Development the necessary competence for Management IS.D.OR.240(g) Policy, and (D.11) activities regarding information Oversight security management Create and maintain a process to GV.PO – ensure that the personnel Personnel Strategy, acknowledge the responsibilities Management IS.D.OR.240(h) Development Policy, and associated with the assigned (D.11) Oversight roles and tasks PR.AC – Verify the identity and Identity trustworthiness of personnel who Management IS.D.OR.240(i) ISM (E.08) Management have access to information and Access systems Control Archive, protect and retain ISM (E.08), PR.DS – Data records and ensure they are Operational IS.D.OR.245 Compliance Security traceable for a specified time (E.09) Correct non-compliance findings upon notification by the Operational IS.D.OR.225 competent authority within the

Annex I to ED Decision 2025/014/R Page 13 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference EU e-CF NIST CSF 2.0 Part-IS main task Management, Part-IS Operational Competence Functions & areas & skills categories period agreed with the competent authority Implement an information security reporting system in Management IS.D.OR.230(a) accordance with Regulation (EU) No 376/2014 Report information security Incident RS.CO – incidents or vulnerabilities to the IS.D.OR.230(b) Management Communicatio Operational competent authority and, under IS.D.OR.230(c) (C.04) ns certain conditions, to others GV.IA – Regularly assess the effectiveness Improvement Operational IS.D.OR.260(a) ISM (E.08) and maturity of the ISMS and Assessment Take actions to improve the ISMS ISM (E.08) GV.IA – if required. Reassess the ISMS Improvement Operational IS.D.OR.260(b) elements affected by the and implemented measures. Assessment Ensure accessibility of the ISM (E.08) GV.OP – IS competent authority to the Management IS.D.OR.235(b) Governance contracted organisation ISM (E.08) GV.PO – Top management ensures that all Strategy, necessary resources are available Management IS.D.OR.240(a)(1) Policy, and to comply with the Regulation Oversight ISM (E.08) Top management establishes and promotes the information GV.PO – IS.D.OR.240(a)(2) security policy and demonstrates Management Strategy, IS.D.OR.240(a)(3) a basic understanding of the Policy, and Regulation Oversight Appoint a responsible person or a ISM (E.08), group of persons with IS.D.OR.240(b) GV.OP – IS Compliance appropriate knowledge to Management IS.D.OR.240(c) Governance (E.09) manage compliance with the IS.D.OR.240(d) Regulation Create and maintain an information security Management IS.D.OR.250 management manual (ISMM)

Annex I to ED Decision 2025/014/R Page 14 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference EU e-CF NIST CSF 2.0 Part-IS main task Management, Part-IS Operational Competence Functions & areas & skills categories Develop a procedure on how to Compliance GV.OP – IS notify the competent authority Management IS.D.OR.255(a) (E.09) Governance upon changes to the ISMS Manage changes to the ISMS and ISM (E.08), notify the competent authority IS.D.OR.255(a) Process RS.IM- Management and/or request for approval of IS.D.OR.255(b) Improvements Improvements changes (E.05)

Annex I to ED Decision 2025/014/R Page 15 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference

Part-IS main task NIST CSF Version 1.1 ISO/IEC 27001 Management, Part-IS Operational Paragraph Annex A Control Function Category Clause :2013 :2022

Establish and operate an

information security Management 4 management system IDENTIFY ID.RM IS.D.OR.200(a) 6.1.1 (ISMS)

Establish the scope of the ID.BE-2 ISMS according to Part-IS Management IDENTIFY ID.BE-4 4.3 requirements IS.D.OR.205(a) ID.AM-5

Implement and maintain

an information security Management IDENTIFY ID.GV-1 5.2 A5.1 A5.1 policy IS.D.OR.200(a)(1)

Identify and review 6.1.2 Management IS.D.OR.200(a)(2) ID.GV-4 information security risks IDENTIFY 8.1 IS.D.OR.205 ID.RA 8.2

Implement information 6.1.3 security risk treatment Management IS.D.OR.200(a)(3) PROTECT PR.PT 8.1 measures IS.D.OR.210 8.3

Implement measures to

detect information DE.AE-3 A11.1.2 A7.2 security events and Management IS.D.OR.200(a)(5) DE.CM-1 A12.4.1 DETECT A8.15 identify those related to IS.D.OR.220 DE.CM-2 A12.4.3 A5.28 aviation safety DE.CM-3 A16.1.7

Implement measures that

have been notified by the Operational IS.D.OR.200(a)(6) 10.1 A6.1.3 A5.5 competent authority

Take appropriate

remedial actions to

address findings notified Both IS.D.OR.200(a)(7) by the competent 10.1 A6.1.3 A5.5 IS.D.OR.225 authority (non-

compliances)

Implement an external RS.CO-2 A6.1.3 information security Management IS.D.OR.200(a)(8) RS.CO-3 A5.5 RESPOND 7.4 A16.1.2 reporting scheme IS.D.OR.230 RS.CO-4 A6.8 A16.1.3 RS.CO-5

Monitor compliance with

this Regulation and report Operational A18.2.1 A5.35 findings to top IS.OI.R.200(a)(12) IDENTIFY ID.GV-3 9.2 A18.2.2 A5.36 management

Annex I to ED Decision 2025/014/R Page 16 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference

Part-IS main task NIST CSF Version 1.1 ISO/IEC 27001 Management, Part-IS Operational Paragraph Annex A Control Function Category Clause :2013 :2022

Protect confidentiality of Operational PR.DS-1 A8.2.2 A5.13 exchanged information IS.D.OR.200(a)(13) PROTECT PR.DS-2 A13.2 A5.14

ID.RA-6 IDENTIFY ID.SC-4

PR.IP-7 Implement and maintain PROTECT PR.IP-10 4.4 a continuous A5.1.2 A5.1 improvement process to 9.1 Management IS.D.OR.200(b) A16.1.7 A5.28 measure the effectiveness DETECT DE.DP-5 9.3 IS.D.OR.260 A17.1.3 A5.29 and maturity of the ISMS 10.1 A18.2.1 A5.35 and strive to improve it 10.2 RS.MI-3 RESPOND RS.IM-2

RECOVER RC.IM-2

ID.AM-6

ID.GV-4

IDENTIFY ID.RM-1

ID.SC-1

ID.SC-2 Document and maintain

all key processes, 4.2 PR.AT-2 A5.1 A5.1 Management procedures, roles and IS.D.OR.200(c) 5.2 PR.AT-4 A6.1.1 A5.2 PROTECT 5.3 responsibilities PR.AT-5

PR.IP-12

DETECT DE.DP-1

RS.CO-1 RESPOND RS.AN-5

Identify all elements ID.AM-1 which could be exposed Management ID.AM-2 to information security IS.D.OR.205(a) IDENTIFY 4.3 A8.1.1 A5.9 ID.AM-4 risks ID.AM-5

Identify the interfaces

with other organisations ID.BE-1

which could result in Management ID.BE-2 IS.D.OR.205(b) IDENTIFY 4.3 exposure to information ID.BE-4

security risks ID.BE-5

ID.RA-1 Identify information ID.RA-2 security risks and assign a Management IS.D.OR.205(c) IDENTIFY ID.RA-3 6.1.2 risk level ID.RA-4

ID.RA-5

Review and update the

risk assessment based on Operational IS.D.OR.205(d) IDENTIFY ID.RM 8.2 A5.7 certain criteria

Annex I to ED Decision 2025/014/R Page 17 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference

Part-IS main task NIST CSF Version 1.1 ISO/IEC 27001 Management, Part-IS Operational Paragraph Annex A Control Function Category Clause :2013 :2022

Develop and implement

measures to address risks Operational PR.IP 6.1.3 and verify their IS.D.OR.210(a) PROTECT PR.PT 8.3 effectiveness

Communicate the ID.AM-3

outcome of the risk ID.BE-1

assessment to ID.BE-2 IDENTIFY management, other Operational ID.BE-4 IS.D.OR.210(b) 8.1 personnel and other ID.RM-3

organisations sharing an ID.SC-3

interface PROTECT PR.IP-7

Establish an internal

information security

reporting scheme to IS.D.OR.200(a)(4) enable the collection and Management A16.1.1 A5.28 IS.D.OR.215(a) IDENTIFY ID.AM-3 7.4 evaluation of information A16.1.2 A6.8 IS.D.OR.215(e) security events from

personnel

Ensure that contracted

organisations report RS.CO-2 Management A15.1.1 A5.19 information security IS.D.OR.215(c) RESPOND RS.CO-4 7.4 A16.1.2 A6.8 events

IDENTIFY ID.RA-1 Analyse internally

reported occurrences to A12.6.1 A8.8 identify information Operational IS.D.OR.215(b)(1)- A16.1.1 A5.24 security events, incidents, (b)(3) A16.1.4 A5.25 and vulnerabilities DE.AE-2

DETECT DE.AE-3

DE.AE-5

A11.1.2 A7.2 Implement measures to DE.AE A12.4.1 A8.8 detect in processes and DETECT DE.CM A12.6.1 A8.15 operations information Operational DE.DP A16.1.1 A8.16 security events which IS.D.OR.220(a) A16.1.2 A5.24 may have a potential A16.1.3 A5.25 impact on aviation safety PROTECT PR.PT-1 A16.1.4 A5.26

A16.1.5 A6.8

Implement measures to

respond to information RS.RP security events that may Operational IS.D.OR.220(b) RESPOND RS.AN A16.1.5 A5.26 cause an information RS.MI security incident

Annex I to ED Decision 2025/014/R Page 18 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference

Part-IS main task NIST CSF Version 1.1 ISO/IEC 27001 Management, Part-IS Operational Paragraph Annex A Control Function Category Clause :2013 :2022

Cooperate on investigations with other organisations that A15.1.2 A5.20 Management RS.AN-3 contribute to the IS.D.OR.215(d) RESPOND A15.1.3 A5.21 RS.AN-5 information security of its A16.1.7 A5.28 own activities

Implement measures to recover from information Operational RC.RP-1 A16.1.5 A5.26 IS.D.OR.220(c) RECOVER security incidents RC.IM-1 A16.1.6 A5.27

Manage risks associated with contracted activities A5.19 with regard to the Management ID.SC-1 A15.1 A5.20 IS.D.OR.235 IDENTIFY management of ID.SC-2 A15.2 A5.21 information security A5.22

Create and maintain a process to ensure that there is sufficient ID.AM-5 personnel to perform all Management IS.D.OR.240(f) IDENTIFY ID.AM-6 7.1 A6.1.1 A5.2 activities regarding ID.GV-2 information security management

Create and maintain a ID.AM-5 process to ensure that IDENTIFY ID.AM-6 the personnel have the necessary competence Management IS.D.OR.240(g) 7.2 A7.2.2 A6.3 for activities regarding information security PROTECT PR.AT-1 management

Create and maintain a process to ensure that the personnel acknowledge the Management ID.GV-2 7.3 IS.D.OR.240(h) IDENTIFY A7.1.2 A6.2 responsibilities associated ID.GV-3 7.4 with the assigned roles and tasks

Verify the identity and trustworthiness of personnel who have Management PR.AC-6 IS.D.OR.240(i) PROTECT 7.1 A7.1.1 A6.1 access to information PR.IP-11 systems

IS.D.OR.245 IDENTIFY ID.RA-4 7.5 A8.2.2 A5.10

Annex I to ED Decision 2025/014/R Page 19 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference

Part-IS main task NIST CSF Version 1.1 ISO/IEC 27001 Management, Part-IS Operational Paragraph Annex A Control Function Category Clause :2013 :2022

A8.2.3 A5.13 PR.AC-2 A11.1.3 A7.3 PR.AC-3 A11.1.4 A7.5 PR.AC-4 Archive, protect and A12.1.3 A8.6 PR.DS-1 retain records and ensure A12.3.1 A8.10 Operational PR.DS-4 they are traceable for a PROTECT A12.4.1 A8.13 PR.DS-5 specified time A12.4.2 A8.15 PR.DS-6 A12.4.3 PR.IP-4

PR.IP-6

PR.PT-1

Correct non-compliance

findings upon notification by the competent A5.31 Operational A18.1.1 authority within the IS.D.OR.225 10.1 A5.35 A18.2 period agreed with the A5.36

competent authority

Implement an

information security

reporting system in Management accordance with IS.D.OR.230(a)

Regulation (EU)

No 376/2014

DETECT DE.DP-3 Report information

security incidents or RS.CO-2 vulnerabilities to the A16.1.1 Operational IS.D.OR.230(b) RS.CO-3 A5.24 competent authority and, RESPOND 7.4 A16.1.2 IS.D.OR.230(c) RS.CO-4 A6.8 under certain conditions, A16.1.3 RS.CO-5 to others

RECOVER RC.CO-3

Regularly assess the A5.1.2 A5.1 effectiveness and Operational IS.D.OR.260(a) 9 A12.7.1 A5.27 maturity of the ISMS A16.1.6 A8.34

Take actions to improve

the ISMS if required.

Reassess the ISMS Operational IS.D.OR.260(b) 10 A5.1.2 A5.1 elements affected by the

implemented measures.

Ensure accessibility of the competent authority to A6.1.3 A5.5 Management the contracted IS.D.OR.235(b) 9.3 A15.1 A5.20

organisation A15.2 A5.22

Annex I to ED Decision 2025/014/R Page 20 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Activity type Reference

Part-IS main task NIST CSF Version 1.1 ISO/IEC 27001 Management, Part-IS Operational Paragraph Annex A Control Function Category Clause :2013 :2022

Top management ensures

that all necessary

resources are available to Management ID.AM-5 IS.D.OR.240(a)(1) IDENTIFY 7.1 A6.1.1 A5.2 comply with the ID.AM-6

Regulation

Top management

establishes and promotes IDENTIFY ID.GV-1

the information security 5.1 A5.1.1 A5.1 Management IS.D.OR.240(a)(2)&( policy and demonstrates 5.2 A7.2.1 A5.4 a)(3) a basic understanding of PR.AT-1 7.4 A7.2.2 A6.3 PROTECT the Regulation PR.AT-4

Appoint a responsible

person or a group of ID.AM-6 IDENTIFY persons with appropriate IS.D.OR.240(b) ID.GV-2 A6.1.1 A5.2 Management 7.1 knowledge to manage IS.D.OR.240(c) A7.2.1 A5.4 7.2 compliance with the IS.D.OR.240(d) A7.2.2 A6.3 PR.AT-1 PROTECT Regulation PR.AT-4

Create and maintain an

information security Management A6.1.3 A5.5 management manual IS.D.OR.250 7.5.1 A12.1.1 A5.37 (ISMM)

Develop a procedure on

how to notify the A6.1.3 Management 7.4 A5.5 competent authority IS.D.OR.255(a) IDENTIFY ID.AM-3 A13.2.1 7.5.1 A5.14 upon changes to the ISMS A13.2.2

Manage changes to the

ISMS and notify the A6.1.3 competent authority Management IS.D.OR.255(a) A5.5 IDENTIFY ID.AM-3 7.4 A13.2.1 and/or request for IS.D.OR.255(b) A5.14 A13.2.2 approval of changes

Appendix III — Examples of aviation services and interfaces

AVIATION SERVICES The following is a non-exhaustive and non-complete list of aviation services that can be used as a basis to identify the scope of the risk assessment for the organisation: — aerodrome & ATM-MET service providers — aeronautical digital mapping services — aeronautical information management (AIM) – external, national, regional — airports

Annex I to ED Decision 2025/014/R Page 21 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

— air traffic control (ATC) – external, superior — air traffic management (ATM) — approach (APP) & area control (ACC) Services – ER ACC, APP ACC — cargo and passenger loading — civil & state airspace user (AU) operations centres — communication infrastructure — flight information & traffic information services (FIS/TIS) data integrator — fuel calculation — navigation infrastructure – ground-based, satellite-based — non-ATM meteorological (MET) service providers — mass & balance calculation — non-aviation users (external) — regional & sub-regional airspace management (ASM) and air traffic flow & capacity management (ATFCM) — static aeronautical data services — sub-regional demand & capacity balancing (DCB) common service providers — surveillance infrastructure – airport, en-route, terminal manoeuvring area (TMA) — route planning — time reference services (external) — tower (TWR) services • aerodrome ATM-MET services provider • aeronautical digital map service • AIM (external) • airport • APP ACC • ATC (external) • ATC superior • ATM • ATM-MET services provider • civil AU operations centre • communication infrastructure • ER ACC • FIS/TIS data integrator • national AIM • navigation infrastructure — ground-based • navigation Infrastructure — satellite-based • non-ATM-MET services provider • non-aviation users (external)

Annex I to ED Decision 2025/014/R Page 22 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

• regional AIM • regional ASM • regional ATFCM • state AU operations centre • static aeronautical data service • sub-regional DCB common service provision • sub-regional/local ATFCM • sub-regional/national ASM • surveillance infrastructure airport • surveillance infrastructure en-route • surveillance infrastructure TMA • time reference (external) • tower (TWR)

Annex I to ED Decision 2025/014/R Page 23 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

INTERFACES Below are some examples of data exchange at the interfaces between organisations interacting in different functional chains, which can be used as a basis for identifying the scope of the risk assessment for the organisation. Note 1: These examples are graphical representations based on the ‘Examples of ecosystem data exchange’ provided in EUROCAE ED-201A, Appendix B - Tables B-14, which can be consulted for further information. Note 2: Although it is not an organisation, an aircraft has been included in all these examples for the sake of completeness of the description of the data exchange. The aircraft should be considered as an element within the scope of the ISMS of the organisation to which it belongs (typically the airline). Any data exchange between aircraft and other systems within the organisation should take into account existing security measures that may have been evaluated as part of aircraft certification (see also GM1 IS.D.OR.D.205(c)).

Airport

AISP

METSP

Maintenance

Design and

Aircraft

Figure 1: Interfaces of other organisations with an airline operator

Annex I to ED Decision 2025/014/R Page 24 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

ATC METSP Airline Airport Maintenance Aircraft

Figure 2: Interfaces of an airline operator with other organisations

Design and Production Maintenance Airline Aircraft

Figure 3: Interfaces of other organisations with a maintenance service provider

Annex I to ED Decision 2025/014/R Page 25 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Design and Production Maintenance Airline Aircraft

Figure 4: Interfaces of a maintenance service provider with other organisations

Annex I to ED Decision 2025/014/R Page 26 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Appendix IV — Part-IS requirements mapping to ISO/IEC 27001:2022 clauses and controls, and considerations on differences

Although Part-IS does not credit ISO/IEC 27001 certification, the practices and methods typically adopted for implementing and maintaining an ISMS under ISO/IEC 27000 largely align with the objectives of this regulation. Therefore, entities that have already implemented an ISMS under ISO/IEC 27001:2022 can use this as a basis for Part-IS compliance. The following provides guidance on how organisations that have already implemented an ISMS compliant with ISO/IEC 27001:2022 can integrate Part-IS requirements into their existing ISMS. Specifically, the table below illustrates how to incorporate the ‘Part-IS particularity’ of each requirement into an existing ISO/IEC 27001-based ISMS in order to achieve Part-IS compliance. This is referred to as ‘Guidance on Part-IS implementation’. Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement IS.D.OR.200(a) Related ISO/IEC 27001:2022 clauses and controls 4. Context of the organisation 6.1.1 Actions to address risks and opportunities - General Part-IS particularity An ISMS designed in the context of an ISO/IEC 27001:2022 ISMS, which is currently not connected to the management systems required by the delegated and implementing acts of Regulation (EU) 2018/1139, including Part-IS, may differ if these different systems do not address the same goals. Part-IS focuses on information security requirements meeting the applicable aviation safety objectives, which have an influence on elements of the ISMS. Also, the ‘interested parties’ and the ‘internal and external issues’ as laid down in Chapter 4 of ISO/IEC 27001:2022 may be adapted to address the requirements of Part-IS for the organisation. Guidance on Part-IS implementation Please note that the point IS.D.OR.200 requirement points to many other Part-IS requirements that the ISMS has to comply with, namely points 205, 210, 215, 220, 225, 230, 235, 240,245, 255, and 260. Further details are provided in the specific chapters on the particular requirement. Regarding the other remaining requirements, not pointing out to other Part- IS requirements, and comparing them with ISO/IEC 27001:2022, there are four requirements left, namely points IS.D.OR.200(a)(1), IS.D.OR.200(a)(6), IS.D.OR.200(a)(12) and IS.D.OR.200(a)(13). IS.D.OR.200(a)(1) Related ISO/IEC 27001:2022 clauses and controls 5.2 Policy A.5.1 Policies for information securities Part-IS particularity

Annex I to ED Decision 2025/014/R Page 27 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement An ISMS designed in the context of an ISO/IEC 27001:2022 ISMS, which is currently not connected to the management systems required by the delegated and implementing acts of Regulation (EU) 2018/1139, may differ as these different systems do often not address the same goals. Part-IS focuses on information security requirements influencing the applicable aviation safety objectives, which in their turn have an influence on the elements of the ISMS. In addition, all domain-specific delegated and implementing acts of Regulation (EU) 2018/1139, namely points ORO.GEN.200(a)(2), ORA.GEN.200(a)(2), CAMO.A.200(a)(2), 145.A.200(a)(2), 21.A.139(c)(1), 21.A.239(c)(1), ATM/ANS.OR.B.005(a)(2), ATCO.OC.C.001(b) and ADR.OR.D.005(b)(2), require a ‘safety policy’, where information security may be integrated. Guidance on Part-IS implementation The policy on information security established in an ISO/IEC 27001:2022 context has to be updated with regard to the potential impact of the risks on aviation safety. At least the elements of AMC1 IS.D.OR.200(a)(1) have to be mentioned in the policy. Therefore, the following elements may need to be added to an existing ISMS policy. The elements in bold and italics are additional guidance that might also be considered. (a) committing to complying with applicable legislation, considering relevant standards and best practices, including safety- and cybersecurity-related standards and guidance published or prescribed by ICAO, EASA or the relevant civil aviation authority; (b) setting objectives and performance measures for managing information security, updated to ensure meeting the applicable aviation safety objectives; (c) defining general principles, activities, processes for the organisation to appropriately secure information and communication technology systems and data, in relation to the information security / safety risk assessment required by point IS.D.OR.205; (d) committing to applying ISMS requirements into the processes of the organisation; (e) committing to continually improving towards higher levels of information security process maturity as per point IS.D.OR.260; (f) committing to satisfying applicable requirements regarding information security (including requirements stemming from civil aviation authorities) and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation; (g) assigning information security as one of the essential responsibilities for all managers; (h) committing to promoting the information security policy through training or awareness sessions within the organisation to all personnel on a regular basis or upon modifications;

Annex I to ED Decision 2025/014/R Page 28 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement (i) encouraging the implementation of a ‘just-culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents; (j) committing to communicating the information security policy to all relevant parties, as appropriate. IS.D.OR.200(a)(6) Related ISO/IEC 27001:2022 clauses and controls 10.1 Corrective actions A5.5 Contact with authorities A5.26 Response to information security incidents A8.8 Management of technical vulnerabilities Part-IS particularity This requirement has no specific counterpart in ISO/IEC 27001:2022. Guidance on Part-IS implementation The policies and procedures, defined as means of compliance with the requirements listed above, should be extended to information security measures mandated by the competent authority. IS.D.OR.200(a)(12) Related ISO/IEC 27001:2022 clauses and controls 9.2. Internal audit 9.3 Management review 10.2 Non-conformity and corrective action A5.36 Compliance with policies, rules and standards for information security Part-IS particularity This requirement is strongly related to the internal audit system and the independent checking function of ISO/IEC 27001:2022. The required feedback system to the accountable manager or the head of the design organisation fits into the requirement of 9.3. In addition, all delegated and implementing acts for the specific domains require a similar ‘compliance monitoring function’, where information security should be integrated as described in AMC1 IS.D.OR.200(a)(12). Guidance on Part-IS implementation The requirements of ISO/IEC 27001:2022 and the delegated and implementing acts of Regulation (EU) 2018/1139 are compatible. Therefore, it will be easy to integrate Part-IS into the audit scope of the ISO/IEC 27001:2022 internal audit system. The role of the accountable manager or the head of the design organisation as defined under point IS.D.OR.240(a) has to be addressed accordingly in the

Annex I to ED Decision 2025/014/R Page 29 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement feedback loop if the role is not already addressed in the management review process. The accountable manager or the head of the design organisation is required to be personally briefed on the key findings so that appropriate decisions can be made. Refer also to GM1 IS.D.OR.200(a)(12). Note: ISO 19011:2018 provides guidance on the establishment of an internal audit system. Specifically, Chapter A.7 ‘Auditing compliance within a management system’ provides useful guidance on how to integrate a compliance monitoring function into an internal audit system. IS.D.OR.200(a)(13) Related ISO/IEC 27001:2022 clauses and controls 7.5.3. Control of documented information (Note) A5.12 Classification of information A5.34 Privacy and protection of personal identifiable information (PII) A8.12 Data leakage prevention Part-IS particularity This requirement is limited to ‘information from other organisations’ and to confidentiality. ISO/IEC 27001:2022 does not differentiate between ‘internal’ or ‘external’ information (as laid down e.g. in ISO 9001:2015 Chapter 8.5.3). The only reference is made in the note in Chapter 7.5.3. Part-IS stresses protection of external information received due to the sensitivity it may have regarding incidents and vulnerabilities disclosure. Insufficient confidentiality protection may result in exploitation of vulnerabilities affecting safety that the original provider of information may not have perceived. Guidance on Part-IS implementation The protection of information, specifically regarding confidentiality (as in ISO/IEC 27002:2022), is related to a set of controls that can be found in Table A.1 (Matrix of controls and attribute values) of ISO/IEC 27002:2022. See also the definition in ISO 27002:2022: 3.1.7 confidential information information that is not intended to be made available or disclosed to unauthorized individuals, entities or processes. The organisation having implemented these controls should take special care that they apply to information received from external information that may result in information security threats if known by unauthorised actors. When this kind of information is further shared with other organisations or authorities, appropriate confidentiality procedures must be put in place and followed (TLP marking, for instance). IS.D.OR.200(b) Related ISO/IEC 27001:2022 clauses and controls 10.1 Continual improvement

Annex I to ED Decision 2025/014/R Page 30 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement Part-IS particularity Part-IS and ISO/IEC 27001:2022 are very similar regarding this requirement. See points IS.D.OR.260 (a) and (b) for subtle differences. Guidance on Part-IS implementation See point IS.D.OR.260 in this table. IS.D.OR.200(c) Related ISO/IEC 27001:2022 clauses and controls 6.3 Planning of changes 7.5.3 Control of documented information Part-IS particularity Control of documented information is one of the key processes in each ISO management system standard, following the ISO ‘high-level structure’ (ISO/IEC Directives part 1 Annex SL), such as ISO/IEC 27001 :2022. For changes, see point IS.D.OR.255. In addition, most of the delegated and implementing acts for the specific domains require a similar need to document, where information security should be integrated. Guidance on Part-IS implementation See points IS.D.OR.250 and IS.D.OR.255 in this table. IS.D.OR.200(d) Related ISO/IEC 27001:2022 clauses and controls 4.3 Determining the scope of the information security management system Part-IS particularity The scope statement and the ‘statement of applicability’ (SOA) are the best references to apply the ‘nature and complexity’. In addition, most of the delegated and implementing acts for the specific domains require a similar need to document, where information security should be integrated. Guidance on Part-IS implementation When determining the scope, it should be noted that Part-IS is delimited to the subject matter as defined in Article 1 of the Regulation(s), which refers to identification and management of information security risks with potential impact on aviation safety. Considering this, the scope of an ISMS under ISO/IEC 27001:2022 may be broader than that required by Part-IS. Some organisational units, processes or locations may fall under what is covered by the ISMS under ISO/IEC 27001:2022, but not within the scope of Part-IS. The opposite may happen too: the scope under ISO/IEC 27001:2022 may be narrower than the one Part-IS would require (e. g. the ISO/IEC 27001:2022 scope covers only the IT department).

Annex I to ED Decision 2025/014/R Page 31 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement In both situations, scope definitions must be compared and adjusted when necessary. Note: See also guidance on point IS.D.OR.205(a) in this table. The scope statement in the ISO/IEC 27001:2022 context is the right place where this clarification is made. IS.D.OR.200(e) Related ISO/IEC 27001:2022 clauses and controls 4.1 Understanding the organisation and its context. Part-IS particularity This is a ‘derogation’ for organisations falling under the applicability of Article 2 of this Regulation. This process is independent from an ISO/IEC 27001:2022 certification process. Guidance on Part-IS implementation If an organisation which already has an established ISMS according to ISO/IEC 27001:2022 decides to embark on this process, the full implementation of Part-IS into the ISMS may be put on hold until the decision of the competent authority is made. To demonstrate that an organisation’s activities, facilities and resources, as well as the services it operates, provides, receives and maintains, do not pose any information security risks with a potential impact on aviation safety either to itself or to other organisations, the existing risk assessment methodology according to ISO/IEC 27001:2022 Chapter 6.1.2 may be used if the methodology is enhanced with a focus on the impact on safety. On the other hand, an existing risk assessment methodology used by the existing safety management system (SMS) could be enhanced by addressing potential information security risks. In any case, the competent authority responsible for the organisation will determine which process and methodology shall be used. This demonstration has to be at least verified and reassessed at regular intervals and as a mandatory part of the organisation’s change process. In case of any doubt about the conclusion, the appropriate civil aviation authority must be contacted. IS.D.OR.205(a) Related ISO/IEC 27001:2022 clauses and controls 4.3 Determining the scope of the information security management system 6.1.2 Information security risk assessment Part-IS particularity This requirement of Part-IS is in line with ISO/IEC 27001:2022, however ISO/IEC 27001:2022 allows a wider focus, whereas Part-IS puts the focus on safety already from the element’s identification stage.

Annex I to ED Decision 2025/014/R Page 32 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement In addition, all of the delegated and implementing acts for the specific domains require a risk assessment process, where information security can be integrated. Guidance on Part-IS implementation AMC1 IS.D.OR.205(a) explains that when conducting an information security risk assessment, the organisation should ensure that each relevant aviation safety impact is identified and included in the ISMS scope, which might not be the case when using ISO/IEC 27001:2022. On the other hand, an ISO/IEC 27001:2022 ISMS focuses its security risk assessment mainly on the business impact of infringement on confidentiality, integrity and availability, their risks and the impact on assets (e. g. loss of IT infrastructure, breach of data). This means that, starting from an ISMS based on ISO/IEC 27001:2022, a complementary analysis has to be made to take into account all the elements related to aviation safety. To bridge the two approaches of safety management systems (SMS) and ISMS, an identified information security risk may be entered as a ‘cause’ or ‘contributing event’ in the aviation-safety-focused risk assessment required by the domain-specific implementing or delegated act. The figure in GM1.IS.D.OR.205(c) provides a good indication of how this bridge could be built. IS.D.OR.205(b) Related ISO/IEC 27001:2022 clauses and controls 4.1 Understanding the organisation and its context 4.3 Determining the scope of the information security management system A5.19 Information security in supplier relationships A5.21 Managing information security in the information and communication technology (ICT) supply chain Part-IS particularity Point IS.D.OR.205(b) focuses on the identification of interfaces with the other organisations. ISO/IEC 27001:2022 4.3 requires considering in point c) the interfaces at and dependencies between activities performed by the organisation and those that are performed by other organisations. So, there is more in Part-IS than that required by ISO/IEC 27001:2022, provided that the scope considered includes safety, as required by point IS.D.OR.205(a). The controls A5.19 and A5.21 are a profound foundation for the requirements of point IS.D.OR.205(b). Guidance on Part-IS implementation ISO/IEC 27001:2022 A5.19 requires the identification of risks associated with the use of suppliers’ products or services. ISO 27002 A5.19 contains additional guidance in points f) to j) on how to manage the risk exposure.

Annex I to ED Decision 2025/014/R Page 33 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement ISO/IEC 27001:2022 A5.21 requires the management of information security risks associated with the ICT products and services supply chain. ISO 27002 A5.21 contains additional guidance in points f), k), l) and m) on how to manage risks through the supply chain. The Part-IS notion about interfaces and supply chain goes beyond the respective ISO/IEC 27001:2022 notion. GM1 IS.D.OR.205(b) requests interfacing organisations to share information about mutual risk exposure (including all data flows) and urges organisations to use ED-201A for that. Point IS.D.OR.205(c) also requires accounting for information acquired by interfacing organisations, which underlines the two-way nature of the considerations. Particular attention should be paid to the Part-IS intent to protect the so-called functional chains. The notion is that while organisations may protect themselves well enough, interfaces between organisations may pose risks to each chain when not accounted for. IS.D.OR.205(c) Related ISO/IEC 27001:2022 clauses and controls 6.1.2 Information security risk assessment Part-IS particularity Point IS.D.OR.205(c) is the ‘heart’ of Part-IS. ISO/IEC 27001:2022 6.1.2 opens a ‘framework’ where the requirements of point IS.D.OR.205 may fit in. It has to be assured that the risk management systems of the ISMS and those required by the SMS regulations (see point IS.D.OR.205(a)) do NOT operate independently, as there might be difficulties in connecting the two systems. Guidance on Part-IS implementation Further to this provision, a proper risk assessment has to be made, taking into account the scope and interfaces described in points IS.D.OR.205(a) and IS.D.OR.205(b). It has to be noted (see also GM1 IS.D.OR.205(c)) that point IS.D.OR.205 does not require the use of any specific information security risk assessment framework, such as ISO 31000, NIST or others, to develop the risk assessment. ISO/IEC 27001:2022 tends to lean towards using ISO 27005 as a risk assessment standard; however, it does not make it mandatory. The key point is that the risk assessment carried out in the application of ISO/IEC 27001:2022 6.1.2 does not necessarily consider safety risks, and may focus on different types of risks. With respect to safety, conditions that may lead to safety consequences are identified as hazards. Their materialisation may be either directly triggered or caused by information security threats which have not been successfully prevented. Information security can thus cause or contribute to a safety consequence in four different ways: (1) it can act as a safety threat; (2) it can have a negative effect on a safety barrier, rendering it less effective than before;

Annex I to ED Decision 2025/014/R Page 34 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement (3) it can directly trigger the materialisation of an already identified hazard; or (4) it can constitute a new, not yet identified, hazard, which can obviously also materialise. By using e.g. the ‘bow-tie method’ regarding information security, a ‘hazard’ would be replaced by a ‘vulnerability’, which can be exploited resulting in information security consequences (e.g. lack or reduction of confidentiality, integrity, availability, authenticity properties). Hence, from a methodology perspective, both considerations are very similar and can be designed to interact (e. g. consequences of the information security bow-tie may connect as causes of the ‘safety bow-tie’). Guidance on organisations that are NOT required to operate an SMS, including safety risk management Any ISO/IEC 27001:2022 risk assessment has to be reviewed and revised by introducing safety impact (consequence) considerations. Any risk matrix stemming from an ISO/IEC 27001:2022 6.1.2 risk assessment is acceptable, provided that it includes safety impacts (consequences), and the results remain within the limitations of ICAO Annex 19. If two different risk assessment schemes are used, they need to be linked accordingly. Guidance on organisations that are required to operate an SMS, including safety risk management In most of the cases, where an organisation is subject to the domain-specific implementing or delegated acts for SMS and operates an ISMS under voluntary compliance with ISO/IEC 27001:2022, it may operate two risk management systems, one for safety under the oversight of a competent authority, and one for information security. The latter may ultimately be certified by an ISO/IEC 27001:2022 accredited body. Each potential risk identified by the ISMS risk management has to be systematically assessed for its potential impact on safety. To establish the connection between the systems, the following approach should be used: (1) If a safety risk assessment is available, it should be able to provide its context and determined target likelihoods for acceptable information security risks to the information security risk assessment process. The context consists of the system architecture, including its preventative and mitigative barriers, the hazards assessed and the safety risks identified. Based upon the information provided, the information security risk assessment can be conducted. Modifications to the system architecture, or any modifications of properties of the preventative or mitigative barriers, as well as the achieved risk properties need to be communicated back to the safety risk assessment process. Based upon this communication, the safety risk assessment has to be updated. In other words: mitigation measures put in place as a result of the information security risk assessment should also be considered as they may not only mitigate, but possibly also create a negative safety impact.

Annex I to ED Decision 2025/014/R Page 35 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement (2) If a safety risk assessment is available, but the information security assessment process identifies a new hazard that was previously unknown to the safety risk assessment, a full hazard assessment of all safety aspects have to be conducted to ensure that the safety risk assessment contains the ‘full picture’ of the newly addressed hazard. (3) The safety risk and the information security risk assessments need to be repeated as described above until all acceptability requirements for all aspects are met. IS.D.OR.205(d) Related ISO/IEC 27001:2022 clauses and controls 6.3 Planning of changes 8.2 Information security risk assessment Part-IS particularity Point IS.D.OR.205(d) is about the subsequent changes to the original risk assessment, due to a change of context or interfaces or knowledge about the risks or lessons learnt. This is equivalent to ISO/IEC 27001:2022 8.2. In both frameworks the reviews are planned and documented. Guidance on Part-IS implementation The same process as that already in place in an ISO/IEC 27001:2022 context can be used to implement point IS.D.OR.205(d), provided that this process has been updated to include safety criteria evaluation of changes that trigger an unplanned update of the risk assessment. Those organisations that have most experienced risk assessment updates at planned intervals will need to be proactive to trigger such updates more often in the situations listed in points IS.D.OR.205(d) (1), (2), (3), and (4) that could affect safety. The triggering criteria and the process should be documented and tested before implementation, for example through table-top exercises. The change management process is key to keep a management system in a solid and stable condition. Considering an established ISMS according to ISO/IEC 27001:2022, the regular updates of the risk assessment based on changes and lessons learned should be effective. The essential focus, introduced by Part-IS, is the ‘impact on safety’, which drives the update assessment. Change management processes focusing on changes that may have impact on safety are also set out in all domain-specific implementing and delegated acts. Without the ‘bridge’ of Part-IS, both systems (ISMS and SMS) are implemented independently, often without considering interdependencies. Part-IS implies the need (and provides the opportunity) to interlink the systems to provide a common risk picture for the organisation, with a focus on safety, but also opening the horizon to information security. IS.D.OR.205(e) Related ISO/IEC 27001:2022 clauses and controls

Annex I to ED Decision 2025/014/R Page 36 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement 6.1.2 Information security risk assessment Part-IS particularity This Part-IS requirement is specific to organisations required to comply with Subpart C of Annex III (Part-ATM/ANS.OR) to Regulation (EU) 2017/373. Guidance on Part-IS implementation Those organisations falling under Subpart C of Annex III (Part-ATM/ANS.OR) to Regulation (EU) 2017/373, which operate an ISO/IEC 27001:2022conformed management system, use safety support assessment instead of the information security risk assessment required in point IS.D.OR.205(c). IS.D.OR.210(a) Related ISO/IEC 27001:2022 clauses and controls 6.1.3 Information security risk treatment 8.3 Information security risk treatment Part-IS particularity Point IS.D.OR.210(a) is about Information security risk treatment, which is widely covered by ISO/IEC 27001:2022, its Appendix A, and ISO/IEC 27002. Point IS.D.OR.210(a) provides however some additional inputs related to the risks that may have a safety impact. Guidance on Part-IS implementation ISO/IEC 27001:2022 6.1.3 is about the definition of the risk treatment plan, while ISO/IEC 27001:2022 8.3 deals with the implementation of the plan, and both are relevant. ISO/IEC 27001:2022 Annex A contains a list of possible information security controls, and therefore should also be used in addition to the already existing controls, to mitigate information security risks having an impact of safety. All the controls of Annex A are detailed in ISO/IEC 27002. Point IS.D.OR.210(a) specifies that the measures selected in the plan have to reduce the consequences on aviation safety associated with the materialisation of the threat scenario. This is in line with point IS.D.OR.205 since the risk treatment phase is a consequence of the risk assessment phase and has to address all the risks that have been evaluated. Point IS.D.OR.210(a) also stipulates that those (protection) measures shall not introduce any new potential unacceptable risks to aviation safety. This is an area that is not directly covered by either ISO/IEC 27001:2022 or ISO/IEC 27002. The requirement addresses the so-called ‘side effects’ when introducing measures into a system (a well-known issue in software development which is also very relevant for information security measures). Preventive or mitigative measures specifically (e.g. physical security, access control) could lead to unintended side effects. Also, the risk treatment of the identified risks should focus on addressing safety via the same linkage/integration of ISMS and safety management.

Annex I to ED Decision 2025/014/R Page 37 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement IS.D.OR.210(b) Related ISO/IEC 27001:2022 clauses and controls 6.1.3.f Information security risk treatment 7.3 Awareness 9.3 Management review A5.19 Information security in supplier relationships A5.21 Managing information security in the ICT supply chain Part-IS particularity Point IS.D.OR.210(b) requires key personnel in the organisation to be informed about the risks, the corresponding threat scenarios and the security risk treatment measures, which result in specific controls covered by Annex A to ISO/IEC 27001:2022 and ISO/IEC 27002. It partially covers IS.D.OR.210(b) by the following requirement: obtain risk owners’ approval of the information security risk treatment plan and acceptance of the residual information security risks. Point IS.D.OR.210(b) has two specific requirements that also have equivalent requirements in ISO/IEC 27001:2022 and ISO/IEC 27002: — Inform the accountable manager or the head of the design organisation of the risk treatment plan — which is a mandatory input to the management review. — Inform the interfacing entities (the same as in point IS.D.OR.205(b)) of all risks shared with them — which is stated in A5.19 Guidance point l). Guidance on Part-IS implementation In addition to the risk owner’s approval requested by ISO/IEC 27001:2022 6.1.3.f, the organisation will need to inform: — the accountable manager or the head of the design organisation of the risk treatment plan. ISO/IEC 27001:2022 9.3. f) defines ‘results of risk assessment and status of risk treatment plan’ as mandatory input for the management review which is the vehicle to inform the accountable managers/heads of the design organisation; — the interfacing entities (the same as in point IS.D.OR.205(b)) of all risks shared with them. ISO/IEC 27002 A5.21 states in point f) ‘defining rules for sharing of information and any potential issues and compromises between the organisations’. GM1 IS.D.OR.205(b) and ED-201A may also be used as guidance on risk sharing. IS.D.OR.215(a) Related ISO/IEC 27001:2022 clauses and controls A5.24 Information security incident management planning and preparation A6.8 Information security event reporting Part-IS particularity

Annex I to ED Decision 2025/014/R Page 38 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement Fully covered by the requirements of A5.24 and A6.8. However, the linkage to the external reporting scheme for the incidents with relation to safety (unsafe conditions) has to be established. Guidance on Part-IS implementation The linkage to the external reporting scheme for the incidents with relation to safety could be described under A5.5 (contact with authorities) in the ISO structure. IS.D.OR.215(b) Related ISO/IEC 27001:2022 clauses and controls A5.25 Assessment and decision on information security events A5.26 Response to information security incidents A5.27 Learning from information security incidents A5.28 Collection of evidence A8.8 Management of technical vulnerabilities Part-IS particularity Fully covered by the requirements from A5.25 to A5.28 and A8.8 with a need to focus on safety impacts. Guidance on Part-IS implementation The requirements of the controls A8.8, A5.25 to A5.28 and the guidance in ISO/IEC 27002:2022 are comprehensive to fulfil the requirements of IS.D.OR.215(b). In accordance with point IS.D.OR.215(b)(1), the impact on safety always needs to be assessed specifically. AMC1 IS.D.OR.215(a)&(b) has also to be considered. IS.D.OR.215(c) A5.19 Information security in supplier relationships A5.20 Addressing information security within supplier agreements A5.21 Managing information security in the information and communication technology (ICT) supply chain Part-IS particularity To be covered under the procedures according to A5.19 and A5.21, as well as under the agreements according to A5.20. Guidance on Part-IS implementation However, this depends on whether the supplier is also subject to Part-IS or not. In the latter case, the external reporting shall be done by the contracting organisation. GM1 IS.D.OR.215(c) provides guidance on the relationship with contracted organisations. IS.D.OR.215(d) Related ISO/IEC 27001:2022 clauses and controls A5.6 Contact with special interest groups

Annex I to ED Decision 2025/014/R Page 39 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement A5.20 Addressing information security within supplier agreements A5.21 Managing information security in the information and communication technology (ICT) supply chain A5.28 Collection of evidence Part-IS particularity The requirements of the controls A5.20, A5.21 and A5.28 and the guidance in ISO 27002:2022 are comprehensive to fulfil the requirements of point IS.D.OR.215(d) in terms of process, but Part-IS will require cooperation with a broader range of organisations. Guidance on Part-IS implementation As ISO/IEC 27001:2022 only focuses on the supply chain and Part-IS requires a broader focus, the process needs to be highlighted to other relevant stakeholders. This may be covered under A5.6. Nevertheless, ISO/IEC 27002 A5.19 has a clear statement under point (i) of the guidance. See also the cooperation in accordance with point IS.D.OR.205(c). IS.D.OR.215(d) Related ISO/IEC 27001:2022 clauses and controls A5.24 Information security incident management planning and preparation A6.8 Information security event reporting Part-IS particularity Fully covered by the requirements of A5.24 and A6.8. Guidance on Part-IS implementation However, the linkage to the external reporting scheme for the incidents with relation to safety (unsafe conditions) shall be established. This could be described under A5.5 (contact with authorities) in the ISO structure. IS.D.OR.220(a) Related ISO/IEC 27001:2022 clauses and controls A5.24 Information security incident management planning and preparation A5.25 Assessment and decision on information security events A5.26 Response to information security incidents A5.27 Learning from information security incidents A5.28 Collection of evidence A5.29 Information security during disruption A7.5 Physical security monitoring A8.16 Monitoring activities Part-IS particularity

Annex I to ED Decision 2025/014/R Page 40 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement Fully covered by the requirements of A5.24 to A5.29, and A7.5 for physical security and A8.16 for technical monitoring. Guidance on Part-IS implementation The requirements of the controls (both reactive and proactive) mentioned above and the guidance in ISO/IEC 27002:2022 are comprehensive to fulfil the requirements of point IS.D.OR.220(a). Again, the impact on safety needs to be assessed, and measures shall be taken to ensure safety. Part-IS refers to ‘unsafe conditions’, which have to be mitigated to an acceptable level. A re-assessment of risks that are related to incidents that have occurred or to a vulnerability that has been identified is mandatory in Part-IS to ensure that no risk becomes unacceptable. Note: Due to historical reasons, information security and safety management use different wording when referring to situations which are more or less the same. The term ‘incident’ is used in a similar way (an event which already happened and infringes safety/security). A vulnerability in the sense of information security could be mapped to the term ‘hazard’ in the area of safety (a situation identified, which is possible to happen, but has not happened so far). IS.D.OR.220(b) Related ISO/IEC 27001:2022 clauses and controls A5.26 Response to information security incidents A5.29 Information security during disruption A7.5 Physical security monitoring A8.8 Management of technical vulnerabilities Part-IS particularity Fully covered by the requirements of A5.26 and A5.29. Guidance on Part-IS implementation The requirements of the control A5.26 and the guidance in ISO/IEC 27002:2022 are comprehensive to fulfil the requirements of point IS.D.OR.220(b). IS.D.OR.220(c) Related ISO/IEC 27001:2022 clauses and controls A5.26 Response to information security incidents A5.29 Information security during disruption Part-IS particularity This requirement is covered by the requirements of A5.26 and A5.29, with the difference that the recovery here is not intended to continuously ensure confidentiality, integrity, availability and integrity; instead, it is intended to maintain or return to an acceptable level of safety.

Annex I to ED Decision 2025/014/R Page 41 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement In addition, some domain-specific implementing and delegated acts of Regulation (EU) 2018/1139 (e.g. points ARO.GEN.200, ATM/ANS.OR.A.070, ADR.OR.B.070) require emergency response planning and/or contingency planning, where information security should be integrated. Guidance on Part-IS implementation Coupled with the requirements of controls A5.26 and A5.28 and the guidance in ISO/IEC 27002:2022, AMC1.IS.D.OR.220(c) should be applied in order to revert as quickly as possible to a safe state. IS.D.OR.225 Related ISO/IEC 27001:2022 clauses and controls 10.2 Non-conformity and corrective action Part-IS particularity This requirement has no specific counterpart in ISO/IEC 27001:2022. Guidance on Part-IS implementation This issue is not covered by the requirements of ISO/IEC 27001:2022, so it is not possible to adapt existing policies and procedures under ISO/IEC 27001:2022 for this requirement. To ensure compliance with this requirement, please refer exclusively to the related AMC and GM. IS.D.OR.230 Related ISO/IEC 27001:2022 clauses and controls A5.5 Contact with authorities Part-IS particularity This requirement is not directly addressed in ISO/IEC 27001:2022. Guidance on Part-IS implementation This issue is not covered by the requirements of ISO/IEC 27001:2022, so it is not possible to adapt existing policies and procedures under ISO/IEC 27001:2022 for this requirement. To ensure compliance with this requirement, please refer exclusively to the related AMC and GM. The reporting requirement should also be considered if the organisation falls under the NIS 2 Directive. IS.D.OR.235(a) Related ISO/IEC 27001:2022 clauses and controls A5.19 Information security in supplier relationships A5.21 Managing information security in the information and communication technology (ICT) supply chain A5.22 Monitoring, review and change management of supplier services Part-IS particularity

Annex I to ED Decision 2025/014/R Page 42 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement ISO/IEC 27001:2022 controls A5.19, A5.21 and A5.29 may cover this requirement. The difference in the requirements of point IS.D.OR.235 is that they are limited to those activities directly related to the ISMS (e. g. internal audits, consultancy for risk assessments, etc.). In addition, all domain-specific implementing or delegated acts require procedures to deal with contracted activities in a wider scope, where information security should be integrated. Guidance on Part-IS implementation This requirement relates only to ISMS activities (e.g. internal audits, risk assessments), not to those activities not directly related to ISMS itself (e. g. hardware, software, IT and OT). The difference in the requirements of point IS.D.OR.235 is that they are limited to those activities directly related to the ISMS (e. g. internal audits, consultancy for risk assessments, etc.). The controls in ISO/IEC 27001:2022 do not exclude those kinds of services, but sometimes they will not be in the focus of the organisation. Therefore, there is no need to establish an independent system for those contractors referred to in point IS.D.OR.235(a). The list of suppliers should be reviewed to ensure that the suppliers providing the services mentioned in point IS.D.OR.235 are covered. IS.D.OR.235(b) Related ISO/IEC 27001:2022 clauses and controls A5.20 Addressing information security within supplier agreements Part-IS particularity Access provided to the authority is not covered in ISO/IEC 27001:2022. Guidance on Part-IS implementation Organisations subject to Part-IS are required to provide access to the competent authority. If the contracted organisation is approved by an authority of another Member State, the different competent authorities will coordinate on which authority will perform oversight of the organisation according to their authority procedures (e.g. Regulation (EU) No 965/2012, point ARO.GEN.300(e)). For contracted organisations not subject to Part-IS, GM1 IS.D.OR.235(b) provides the content to be introduced either in the ‘general terms and conditions of trade’ of the contracting organisation, or if standard general terms and conditions are used (e. g. for COTS-products), the content of the GM has to be arranged on a contractual basis (e. g. through a side letter). AMC1.IS.D.OR.235(b) should be considered in conjunction with ISO/IEC 27001:2022 A5.20. IS.D.OR.240(a) Related ISO/IEC 27001:2022 clauses and controls IS.D.OR.240(e) 5.1 Leadership and commitment

Annex I to ED Decision 2025/014/R Page 43 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement 5.3 Organisational roles, responsibilities and authorities 7.1 Resources A5.2 Information security roles and responsibilities Part-IS particularity ISO/IEC 27001:2022 does not require a specific role such as the ‘accountable manager’ or ‘head of the design organisation’. Guidance on Part-IS implementation The implementation of the requirements of point IS.D.OR.240(a) can be covered by the implementation of ISO/IEC 27001:2022 requirements mentioned above, provided that the role of accountable manager/head of the design organisation is clearly defined and meets the requirements in point IS.D.OR.240(a). The requirement of point IS.D.OR.240(a)(3) has to be set in line with the roles in A5.2 (where an accountable manager or the head of the design organisation is not envisaged). However, the measures in A6.3 should be used to ensure the competency of the accountable manager or the head of the design organisation (point IS.D.OR.240(a)(3)). IS.D.OR.240(b) Related ISO/IEC 27001:2022 clauses and controls IS.D.OR.240(c) 5.3 Organisational roles, responsibilities and authorities 7.1 Resources A5.2 Information security roles and responsibilities A5.3 Segregation of duties Part-IS particularity This requirement is not directly addressed in ISO/IEC 27001:2022. Guidance on Part-IS implementation The implementation of the requirements of A5.2 and A5.3 should be used as a basis to fulfil the provisions of points IS.D.OR.240 (b) and (c), but some adaptation may be needed. This issue is covered in A5.2, but A5.3 may also be applicable. In addition, similar requirements for the ‘safety roles’ are laid down in the domainspecific ‘safety’ implementing or delegated acts of Regulation (EU) 2018/1139. AMC1 IS.D.OR.240(b) should be considered. IS.D.OR.240(d) Related ISO/IEC 27001:2022 clauses and controls 4.3 Determining the scope of the information security management system A5.2 Information security roles and responsibilities A5.3 Segregation of duties

Annex I to ED Decision 2025/014/R Page 44 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement Part-IS particularity The implementation of the requirements of A5.2 and A5.3, as well as the guidance of ISO/IEC 27002, allow the delegation of responsibility within organisations. Guidance on Part-IS implementation This option might be useful for large organisations or groups, where the ISMS is implemented as an ‘umbrella function’ over a group of organisations, where not all of them are subject to Part-IS. The implementation of a ‘group CISO’ or an enterprise-wide ISMS could make use of this option in Part-IS. Nevertheless, the common responsible person has to fulfil the competency requirements of point IS.D.OR.240(a)(3). This might be relevant in cases where the other activities of the organisation or group are not related to aviation. IS.D.OR.240(f) Related ISO/IEC 27001:2022 clauses and controls 7.1 Resources Part-IS particularity The requirements of 7.1 should be implemented. Guidance on Part-IS implementation A systematic capacity planning of human resources is a key element of any management system. Therefore, such a process should be established in an ISMS. The possible additional requirement stemming from Part-IS has to be assessed, and the capacity planning updated accordingly. The targeted safety levels set in the safety/information security assessment should never be jeopardised by a lack of resources, even temporarily. AMC1 IS.D.OR.240(f) should be considered. IS.D.OR.240(g) Related ISO/IEC 27001:2022 clauses and controls 7.2 Competency A6.3 Information security awareness, education and training Part-IS particularity The implementation of the requirements of 7.2 and A6.3 is sufficient to cover the requirement. Guidance on Part-IS implementation A systematic competency management process of staff is a key element of any management system. Therefore, such a process should be established in an ISMS. The possible additional requirement stemming from Part-IS has to be assessed and the competency requirements updated accordingly.

Annex I to ED Decision 2025/014/R Page 45 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement AMC1 IS.D.OR.240(g) should be considered. IS.D.OR.240(h) Related ISO/IEC 27001:2022 clauses and controls A6.2 Terms and conditions of employment Part-IS particularity The implementation of the requirements of A6.2 with some adaptation would be sufficient to cover the provision of point IS.D.OR.240(h). Guidance on Part-IS implementation Point IS.D.OR.240(h) is (at least partially) covered by ISO/IEC 27001:2022 A.6.2 ‘The employment contractual agreements have to be state the personnel’s and the organisation’s responsibilities for information security.’ and A.6.4 ‘disciplinary process’ (see ‘Just Culture’). It depends on the organisational culture and on whether job descriptions or role assignments need to be formally acknowledged. In many organisations, the assigned jobs and roles are mutually acknowledged by performing the tasks assigned. IS.D.OR.240(i) Related ISO/IEC 27001:2022 clauses and controls A5.19 Information security in supplier relationships A6.1 Screening A7.2 Physical entry A8.3 Information access restriction A8.5 Secure authentication Part-IS particularity The implementation of the requirements of A5.19, A6.1, A7.2, A8.3 and A8.5 might be sufficient controls to cover this requirement for the personnel of the organisation, as well as for contractors and suppliers. Guidance on Part-IS implementation All the controls established in an ISO/IEC 27001:2022-compliant ISMS are designed to ensure the confidentiality and integrity of information. The implementation of those controls will provide sufficient protection to ensure compliance with this requirement. AMC1 IS.D.OR.240(i) should be considered. IS.D.OR.245(a) Related ISO/IEC 27001:2022 clauses and controls 7.5 Documented information A5.9 Inventory of information and other associated assets A5.13 Labelling of information A8.10 Information deletion

Annex I to ED Decision 2025/014/R Page 46 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement A8.13 Information backup Part-IS particularity Record-keeping and retention are an inherent part of the document control system under 7.5 of ISO/IEC 27001:2022. The controls A5.9, A5.13, A8.10 and A8.13 also apply. Guidance on Part-IS implementation Chapter 7.5.1 b) states that the ISMS has to include ‘documented information determined by the organisation as being necessary for the effectiveness of the information security management system.’ This includes the records defined in point IS.D.OR.245(a)(1). Chapter 7.5.3 requires, under f), also document control for retention and disposition. Part-IS requirements have to be integrated into the existing system, especially the minimum duration of record-keeping of five years. The minimum set of records, as defined in point IS.D.OR.245(a)(1) should be covered in the inventory of assets. For the coverage, the content of GM1 IS.D.OR.245 also applies. As records are not only information assets, the requested ‘record retention policy’ may be integrated into a wider policy as recommended by ISO/IEC 27002:2022 above. AMC1 IS.D.OR.245(a)(1)(vi)&(a)(5) should be implemented. IS.D.OR.245(b) Related ISO/IEC 27001:2022 clauses and controls 7.5 Documented information A5.9 Inventory of information and other associated assets A5.10 Acceptable use of information and other associated assets A5.13 Labelling of information A5.34 Privacy and protection of personal identifiable information (PII) A8.10 Information deletion A8.13 Information backup Part-IS particularity Record-keeping and retention are an inherent part of the document control system under 7.5 of ISO/IEC 27001:2022. The controls A5.9, A5.13, A8.10 and A8.13 will also apply and, due to GDPR issues specifically, also A5.10 and A5.34. Guidance on Part-IS implementation Chapter 7.5.1 b) states that the ISMS has to include ‘documented information determined by the organisation as being necessary for the effectiveness of the information security management system.’ This includes the records defined in point IS.D.OR.245(a)(1). Chapter 7.5.3 requires, under f), also document control for retention and disposition. Part-IS requirements have to

Annex I to ED Decision 2025/014/R Page 47 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement be integrated into the existing system, especially the minimum duration of record-keeping of five years. However, whereas there is no retention duration specified in ISO/IEC 27001:2022, point IS.D.OR.245(a) specifies three years after the person has left the organisation. As these records fall under the GDPR Regulation, each organisation has to ensure that they are handled accordingly. It is recommended that the procedures are used not only for records related to ISMS, but also for the entire HR personnel files of the staff. IS.D.OR.245(c) Related ISO/IEC 27001:2022 clauses and controls 7.5 Documented information A5.13 Labelling of information Part-IS particularity Record-keeping and retention are an inherent part of the document control system under 7.5 of ISO/IEC 27001:2022 as well as the control A5.13. Guidance on Part-IS implementation Chapter 7.5.3, under a), requires for the information that ‘it is available and suitable for use, where and when it is needed’. Part-IS requirements have to be integrated into the existing system. ISO 27002:2022 A5.13 states ‘Procedures for information labelling should cover information and other associated assets in all formats.’; therefore, the Part-IS requirement is fulfilled with control A5.13. A series of AMC material to the implementing and delegated acts regarding safety (e.g. AMC1 ARA.GEN.220(a), AMC1 145.A.55) also covers this issue. IS.D.OR.245(d) Related ISO/IEC 27001:2022 clauses and controls 7.5 Documented information A5.10 Acceptable use of information and other associated assets A5.12 Classification of information A5.33 Protection of records A8.12 Data leakage prevention Part-IS particularity Record-keeping and retention are an inherent part of the document control system under 7.5 of ISO/IEC 27001:2022. The controls A5.10, A5.12, A5.33 and A8.12 will also apply. Guidance on Part-IS implementation Chapter 7.5.3, under d), requires ‘storage and preservation, including the preservation of legibility’. Part-IS requirements have to be integrated into the existing system.

Annex I to ED Decision 2025/014/R Page 48 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement The application of A5.33 and A8.12 has a strong relationship to A7.5 (Protecting against physical and environmental threats), A7.10 (Storage media), A8.3 (Information access restriction), A8.13 (Information backup), A8.14 (Redundancy of information processing facilities), A8.15 (Logging), A8.17 (Clock synchronization) and A8.24 (Use of cryptography). IS.D.OR.250(a) Related ISO/IEC 27001:2022 clauses and controls 7.5 Documented information A5.13 Labelling of information Part-IS particularity Document control is an inherent part of the ISMS under 7.5 of ISO/IEC 27001:2022. The control A5.13 is also an ‘anchor point’ for this requirement. ISO/IEC 27001:2022 does not specifically request a document called ‘information security management manual’, made available to the authority. Guidance on Part-IS implementation Chapter 7.5.1 b) states that the ISMS has to include ‘documented information determined by the organisation as being necessary for the effectiveness of the information security management system’ which will allow the inclusion of the ISMS manual in the documentation. Part-IS requires a specific ISMS manual (ISMM), made available to the competent authority. It has to be made clear to the competent authority which set of documented information constitutes the ‘approved manual’. The document ‘statement of applicability’ (SOA), mandatory for all ISO/IEC 27001:2022-certified organisations may be helpful (e.g. by adding an additional column to label specific documents as part of a ‘virtual’ ISMS Manual). GM1 IS.D.OR.250(a) also provides associated guidance. It has to be ensured that all information listed in point IS.D.OR.250(a) is covered. IS.D.OR.250(b) Related ISO/IEC 27001:2022 clauses and controls IS.D.OR.250(c) 7.5 Documented information A5.5 Contact with authorities Part-IS particularity Document control is an inherent part of the ISMS under 7.5 of ISO/IEC 27001:2022. Guidance on Part-IS implementation The use of the same procedure as the one implemented for the ‘safety regulations’ (see above) is recommended also for the approval, update and communication processes with the competent authority. Many organisations have their documented information available via document management systems (e.g. MS SharePoint). The access of the

Annex I to ED Decision 2025/014/R Page 49 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement competent authority to these systems have to be managed in accordance with the rules of any other external access in respect of A5.15, A5.18, A6.6, A7.9, A8.3, A8.7, A8.11, and A8.24. IS.D.OR.250(d) Related ISO/IEC 27001:2022 clauses and controls 7.5 Documented information Part-IS particularity This possibility of ISMM integration with other expositions or manuals has no specific counterpart in ISO/IEC 27001:2022. However, following the ISO ‘Annex SL’ structure, ISO/IEC 27001:2022 enables an easy integration of other management system standards. Guidance on Part-IS implementation There is a tendency in the aviation industry to integrate different management systems, depending on the structure of the organisation. IS.D.OR.255(a) Related ISO/IEC 27001:2022 clauses and controls 6.3 Planning of changes A5.5 Contact with authorities Part-IS particularity Change management is an inherent part of the ISMS under 6.3 of ISO/IEC 27001:2022, but there is no provision for approval of a procedure by a competent authority. Guidance on Part-IS implementation The use of the same procedure as the one implemented for the ‘safety regulations’ (see above) is recommended also for the approval of changes not requiring prior approval by the competent authority. This procedure should be extended to Part-IS in agreement with the competent authority. Note: This recommendation will only work if the competent authority is the authority as laid down in Article 6(1) of Regulation (EU) 2023/203 or Article 5(1) of Regulation (EU) 2022/1645. WARNING: An organisation with a derogation approval in accordance with point IS.D.OR.200(e) needs to assess for all changes (also those not requiring prior approval) whether the criteria for the approved derogation are still valid. If not, the change needs the approval of the competent authority/authorities prior to being implemented. IS.D.OR.255(b) Related ISO/IEC 27001:2022 clauses and controls 6.3 Planning of changes A5.5 Contact with authorities Part-IS particularity

Annex I to ED Decision 2025/014/R Page 50 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement Change management is an inherent part of the ISMS under 6.3 of ISO/IEC 27001:2022. However, ISO/IEC 27001:2022 does not require any kind of approval by a competent authority. Guidance on Part-IS implementation The use of the same procedure as the one implemented for the ‘safetyregulations’ (see above) is recommended also for the approval of changes in agreement with the competent authority. Note: This recommendation will only work if the competent authority is the authority as laid down in Article 6(1) of Regulation (EU) 2023/203 or Article 5(1) of Regulation (EU) 2022/1645. IS.D.OR.260(a) Related ISO/IEC 27001:2022 clauses and controls 9.3 Management review 10.1 Continual improvement A5.35 Independent review of information security Part-IS particularity This requirement reflects a combination of requirements 9.3 and 10.1 of ISO/IEC 27001:2022 with references to requirements 4.4 and 5.2. While ISO/IEC 27001:2022 focuses on ISMS suitability, adequacy and effectiveness, point IS.D.OR.260(a) requires also a periodical maturity assessment of the ISMS. Guidance on Part-IS implementation ISO/IEC 27001:2022, 4.4 shows a clear requirement (‘shall’) for ISMS maintenance and improvement. The top management has a responsibility for continuous ISMS improvement as per ISO/IEC 27001:2022 5.2(d). The planning section also requires continuous improvement (ISO/IEC 27001:2022 6.1.1(c)). Point IS.D.OR.260(a) requires an assessment of the effectiveness and maturity of the ISMS on a calendar basis or following an information security incident. This assessment should be performed by using indicators. ISO/IEC 27001:2022 Chapter 9.3.1 defines a very similar approach for the management review process. Chapter 10.1 indicates a more independent process to improve the ISMS. The process in Chapter 10.1 is seen as more of a bottom-up approach, whereas that in Chapter 9.3 is intended to be topdown. The results from A5.35 should all be used as inputs for continuous improvement. Point IS.D.OR.260(a) also requires a maturity assessment of the ISMS. Each organisation should establish which maturity model will be followed and which targeted maturity level is expected to be reached and by when.

Annex I to ED Decision 2025/014/R Page 51 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Part-IS ISO/IEC 27001:2022 mapping and specific guidance requirement For the maturity assessment, point (b) of AMC1 IS.D.OR.260(a) and GM1 IS.D.OR.260(a) provides guidance on how to ensure compliance with point IS.D.OR.260(a). IS.D.OR.260(b) Related ISO/IEC 27001:2022 clauses and controls 10.2 Non-conformity and corrective action A5.7 Threat intelligence Part-IS particularity Point IS.D.OR.260(b) addresses the improvement measures, i.e. corrections and corrective actions for the deficiencies detected in point IS.D.OR.260(a) and the continuous improvement process. This requirement reflects mainly requirement 10.2 of ISO/IEC 27001:2022, even if the term used is ‘non-conformity’, while point IS.D.OR.260(b) uses the term ‘deficiencies’. Deficiency has a broader meaning than non-conformity. It encompasses the case of a targeted maturity level that would not be reached at the planned date; that would be a deficiency but not necessarily a non-conformity. Guidance on Part-IS implementation The provisions listed in ISO/IEC 27001:2022 10.2 can be used to take corrective actions, to resolve both non-conformities and maturity level gaps.

Annex I to ED Decision 2025/014/R Page 52 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Appendix V — Proportionality considerations related to safety relevance and aspects of complexity

The following is a non-exhaustive, non-binding, list of activities related to the implementation of the ISMS under this Regulation. These activities are proposed in association with a set of indicators, with activities suggested at the lower and upper ends of the scale. Organisations are encouraged to assess their own level for each indicator, selecting or adapting the proposed activities based on their specific information security risks and organisational context. This approach helps to keep the activities proportionate to the overall safety relevance and complexity of the organisation. Indicator of the degree of safety relevance: the organisation’s role in the functional chain, and number and criticality of interfacing organisations The organisation’s role in the functional chain and its overall contribution to the safety of related functional processes are key indicators of safety relevance. This should impact the depth of risk assessment required and the level of assurance needed to ensure the effectiveness of measures implemented to mitigate unacceptable risks. Low safety relevance: organisations whose role in the functional chain and their interfaces do not pose a risk of unsafe conditions. The following approach may be adopted: Risk assessment and treatment — Simplified risk assessment: A streamlined risk assessment process that prioritises risks based on their potential impact on safety is used. The assessment focuses on high-impact areas; more detailed assessments are performed only where and if necessary. — Risk treatment prioritisation: A risk treatment plan that prioritises high-impact risks with costeffective measures is adopted. In such cases, cost-effective controls that reduce risks to acceptable levels may be used. These controls can often leverage existing processes, physical controls or technology. High safety relevance: organisations whose role in the functional chain and their interfaces may pose a risk of unsafe conditions The following approach may be adopted: Risk assessment and treatment Detailed risk assessments: Detailed and often more frequent risk assessments are carried out for those elements that have been identified as having a relevant safety impact, i.e. an unsafe condition. Indicator of complexity 1: complexity of the organisational structure and hierarchies The complexity of an organisation’s structure — typically determined by the number of staff, departments and hierarchical layers — directly influences the level of internal coordination required and the extent to which information exchange needs to be formalised and proceduralised. Low complexity: organisations characterised by a combination of limited number of staff members, few hierarchical layers and departments The following approaches may be adopted:

Annex I to ED Decision 2025/014/R Page 53 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

(a) Policy and procedure simplification — Streamlined documentation: Policies and procedures can be concise, clear and easy to read. Documents are kept short and simple to make them easily understandable. Templates can be used in order to expedite the creation of the necessary documentation. — Focus on key policies: During the development, the key policies have been prioritised in order to address the most critical aspects of information security, such as management commitment, access control and incident response. (b) Employee training and awareness — Targeted training programmes: Focused training programmes that target the specific roles and responsibilities of employees are provided. The training is relevant to the organisation’s specific risks and operational context. — Security culture: A culture of information security awareness is encouraged throughout the organisation. Short training sessions and awareness campaigns are conducted on a regular basis. (c) Outsourcing and partnerships — Outsourcing: For areas where the organisation lacks expertise, outsourcing to providers of managed-security services is adopted. — Collaboration with peers: Information-sharing with similar organisations (e.g. through the European Centre for Cyber Security in Aviation (ECCSA)) or industry groups is carried out. Collaboration provides insights to evaluate the evolution of the security environment with limited effort. (d) Engagement with management Simplified management reporting: Reports to management are concise and focused on key metrics that demonstrate the effectiveness of the ISMS. Continued support and resource allocation from top management is ensured. (e) Compliance monitoring and continuous improvement — Regular but scaled audits: Internal audits are regularly conducted, but the effort is scaled to the organisation’s size and complexity. The focus is on the most critical areas and the audit results are provided to the accountable manager or the head of the design organisation and utilised to guide continuous improvement. — Agile review process: The ISMS is regularly reviewed and, if necessary, adapted to ensure that it remains aligned with the organisation’s evolving needs and threats. High complexity: organisations characterised by a combination of large number of staff members, hierarchical layers and departments and interfaces The following approaches may be adopted: (a) Robust governance structure — Information security governance: Governance implementation to oversee the ISMS are present. This is to ensure alignment with the organisation’s safety and security objectives.

Annex I to ED Decision 2025/014/R Page 54 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

This governance should operate through formal committees or working groups that include representatives from senior management, safety, information technology, legal and key business units. — Metrics and reporting: Comprehensive metrics and reporting structures to track the effectiveness of the ISMS are implemented. Report on key performance indicators (KPIs) to senior management and the management board are provided to ensure ongoing support and resource allocation. (b) Extensive policy and procedure framework — Detailed policies and procedures: Although streamlined documentation is still the overall objective, more complex organisations may require a broader range of policies and procedures to cover different business units and departments, compliance requirements and operational processes. — Policy harmonisation: Policies are harmonised across the organisation to avoid conflicting practices between different departments or regions. This requires a centralised governance model to oversee policy development and enforcement. (c) Risk assessment and treatment — Cross-risk assessments: Cross-risk assessments include assessing risks across various departments, geographic locations and technological platforms. — Risk aggregation and correlation: With a larger volume of information, risks assessments are aggregated and correlated to identify systemic issues and ensure that risks are managed and escalated at an organisational level, not just within individual silos. (d) Comprehensive training and awareness programmes — Role-based training: Extensive role-based training programmes tailored to different functions within the organisation are implemented. For example, IT staff, executives and end-users all have different levels of training specific to their roles. — Continuous security awareness campaigns: Security awareness campaigns using various methods (e.g. phishing simulations, workshops and e-learning modules) are continuously deployed to keep security top-of-mind for all employees across the organisation. (e) Enhanced contracted activities management — Supply chain risk management: Thorough information security assessments of contracted organisations and ongoing monitoring of third-party risks are carried out. Information security requirements are integrated into contracts. (f) Comprehensive incident management — Security monitoring and incident response capability: In order to monitor security events around the clock, manage incidents and coordinate response efforts across the organisation, structured security operations are established. Depending on the organisation's resources, this can be achieved through a dedicated security operations centre (SOC), a virtual SOC, managed security services or other appropriate solutions that ensure effective coverage.

Annex I to ED Decision 2025/014/R Page 55 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

— Complex incident response plans: Detailed incident response plans that cover a variety of scenarios, including cross-departmental coordination, communication strategies and operational continuity planning are developed and maintained. — Crisis simulation exercises: Crisis simulation exercises that involve key stakeholders across the organisation are regularly conducted to test the effectiveness of incident response and operational continuity plans. (g) Continuous improvement and compliance monitoring programmes — Internal audits: Comprehensive internal audits are regularly conducted to assess compliance with the ISMS and identify areas for improvement. — Audits of contracted organisations: To ensure compliance with the organisation’s security and safety objectives, audits of contracted organisations are conducted at a frequency proportionate to the relevance of the contracted activities to security and safety. Using the results of existing relevant audits is also encouraged to reduce the burden. — Continuous improvement programmes: A continuous improvement process to update and refine the ISMS based on audit findings, incident post-mortems and changes in the threat landscape is implemented. Indicator of complexity 2: complexity of the ICT systems and data used by the organisation The complexity of the information and communication technology systems and data used by the organisation, and their connection to external parties, directly influences the level of customisation and tailoring required for risk management and incident detection, response and recovery. Low complexity: organisations characterised by a combination of usage of a few ICT tools and utilisation of standard ICT products The following approaches may be adopted: (a) Use of standards and tools — Leverage ISO/IEC 27001 controls as a baseline: ISO/IEC 27001 Annex A provides a catalogue of controls that are selected based on the results of the risk assessment. Similarly, NIST SP 800-53 offers a comprehensive set of controls that can be adapted to specific threats and operational requirements. Aligning control selection with risk assessment outcomes ensures that the controls are suitable for the specific threats and vulnerabilities identified, while reducing the effort involved in designing controls from scratch. Additionally, using the controls as a checklist helps to ensure that critical areas are addressed. To ensure full alignment with aviation-specific information security requirements under Part-IS, it is also recommended to consult the Part-IS versus ISO/IEC 27001:2022 comparison guide. — Simplified incident management: A basic incident management process that allows for quick identification, reporting and response to security incidents is adopted. Lessons learned from incidents are in any case integrated into the ISMS for continuous improvement.

Annex I to ED Decision 2025/014/R Page 56 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

— Automated tools: Automated tools for monitoring, logging and managing security incidents are used in order to reduce manual effort while maintaining continuous compliance. (b) Documentation and record-keeping — Essential records: Only records that are essential to demonstrate compliance and the effectiveness of the ISMS are kept. Excessive documentation that does not add value or is burdensome to maintain is avoided. — Use of digital solutions: Digital tools are used for document management to simplify access and version control, and to ensure the security of records. High complexity: organisations characterised by a combination of usage of several and diverse ICT tools, amongst which bespoke ICT solutions The following approaches may be adopted: (a) Advanced security technologies — Integration of advanced security tools: Security technologies like security information and event management (SIEM), data loss prevention (DLP), and endpoint detection and response (EDR) systems are utilised to help manage the scale and complexity of monitoring, detecting and responding to security incidents across the organisation. — Automated threat intelligence: Automated threat intelligence platforms are used to enable real-time threat detection and response across the broad threat surface. (b) Documentation and record-keeping — Detailed documentation: Extensive documentation of all ISMS processes, risk assessments, incident reports and compliance activities is carried out. — Record retention: Records and data are widely collected, retained and securely stored, and are accessible over extended periods.

Annex I to ED Decision 2025/014/R Page 57 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Appendix VI — Adaptation of the EU Cybersecurity Skills Framework (ECSF)

Annex I to ED Decision 2025/014/R Page 58 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 59 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 60 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 61 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 62 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 63 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 64 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 65 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 66 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 67 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 68 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 69 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 70 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 71 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 72 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 73 of 74

AMC & GM to Part-IS.D.OR Issue 1, Amendment 1

Annex I to ED Decision 2025/014/R Page 74 of 74

Fotnoter

  1. information security
  2. compromise Safety N
  3. Consequences likelihood, Threat Hazards
  4. consequences and
  5. Risk Y
  6. context Mitigative
  7. Preventative Top Acceptable?
  8. Barriers Barriers Event
  9. Context and target information security
  10. compromise Information Vulnerability Security (IS)
  11. Threat Consequence s
  12. Preventative Information Mitigative Likelihood
  13. Controls Compromise Controls
  14. Begin derogation approval process
  15. Apply for Request derogation preliminary See note 1 approval information
  16. See note 2
  17. Conduct Candidate meets pre-assessment criteria?
  18. Involvement of more expertise
  19. Yes No
  20. Request and obtain Conduct risk complete assessment documentation
  21. Inspectors of SMS
  22. Evaluate evidences Information security expert
  23. Yes Safety Officer
  24. Candidate meets No
  25. Derogation accepted Derogation denied
  26. Issue / decline
  27. End of derogation process
  28. Airport capacity, BPM – luggage treatment state, PHMR identification, recording terminals
  29. Initial flight plan processing system (IFPS) Collaborative decision-making (CDM) ATSP
  30. Daily operational briefing
  31. AIS - NOTAMs Airline
  32. Weather forecast and observations / METAR
  33. Consolidated maintenance data, completed checklist with performed activities
  34. Operational documentation
  35. Software updates Production
  36. QAR, FDR data AOC data
  37. Centralised maintenance system (CMS), Aircraft conditioning management system (ACMS) report
  38. IFPS, Target take-off time, ATC flight plan proposal, Enhanced tactical flow management, CDM
  39. AIREP encountered weather info
  40. Airport capacity needs, boarding pass data, TOBT, Airlines attendance, PHMR identification, PNR – passenger info, BSM – luggage data
  41. EFB load, specific SW and configuration, maintenance procedures, request for intervention
  42. Take-off performance data Meteo data Parking data NOTAM, Chart, QNH, Temperature Weight and Balance AOC data
  43. EFB load
  44. Accounts & roles management
  45. Maintenance procedures
  46. Software loads
  47. Data Base
  48. Logistic Data
  49. EFB load, specific SW and configuration, maintenance procedures, request for intervention
  50. Raw maintenance data
  51. Logisitic Data
  52. Consolidated maintenance data
  53. Completed checklist with performed activities
  54. Software loads Data Base
  55. EFB loads Hardware Maintenance requests