EASA Part-IS - Information Security in Aviation
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Implement logical and physical access controls to aviation information systems based on least privilege.
- Access control policy
- MFA enforcement records
- Quarterly access reviews
- Physical access logs to data centres
- Privileged accounts without MFA
- Access reviews skipped
- Shared accounts in operations
Change Management
Manage changes to the ISMS so that compliance and effectiveness are preserved, with prior approval where required by the authority.
- Change management procedure
- Change records
- Approval correspondence with authority where applicable
- Changes implemented without impact assessment
- Authority not notified of significant changes
- No rollback plan
Compliance
Define corrective actions, implement them, and report progress in response to authority findings.
- Corrective action plan
- Findings register
- Closure evidence submitted to authority
- Root cause analysis absent
- Actions not tracked to closure
- Late submission to authority
Cryptography
Apply cryptographic controls to protect aviation data in transit and at rest, with managed key lifecycle.
- Cryptography policy
- Key management procedures
- TLS configuration scans
- HSM evidence
- Deprecated TLS versions in use
- Keys never rotated
- No HSM for high-impact keys
Documentation
Maintain records of ISMS activities, risk assessments, incidents, training, and audits for the periods defined by the authority.
- Records retention schedule
- Audit logs of record access
- Sample records covering retention period
- Retention periods inconsistent with authority requirements
- Records not tamper evident
- No retrieval test
Produce and maintain an Information Security Management Manual describing how the organisation complies with Part-IS.
- Current ISMM
- Approval and revision history
- Distribution list
- Cross-reference to Part-IS requirements
- ISMM lacks cross-reference matrix
- Out of date sections
- Not linked to safety management manual
Governance
Establish, implement, and maintain an ISMS proportionate to the organisation's nature, size, and information security risks affecting aviation safety.
- ISMS charter
- Scope statement covering aviation activities
- Approved information security policy
- Management review minutes
- ISMS scope omits OT or maintenance systems
- No board-level approval
- Policy not aligned with safety management system
Continually improve the effectiveness of the ISMS based on audits, reviews, incidents, and changing threats.
- Management review minutes
- KPI dashboard
- Lessons learned register
- Improvement plan
- No measurable KPIs
- Management review skipped
- Lessons learned not actioned
Human Resources
Ensure personnel are competent for their information security responsibilities and have appropriate authority.
- Role descriptions including IS duties
- Competency matrix
- Training plan
- Background checks where applicable
- No competency definition for ISMS lead
- Training not aviation-specific
- Background screening absent for sensitive roles
Incident Management
Operate an internal scheme for staff and contractors to report information security events that may affect aviation safety.
- Internal reporting procedure
- Just culture policy
- Reporting metrics
- Training records for personnel
- No anonymous channel
- Reports not triaged within defined SLA
- Personnel unaware of duty to report
Detect, respond to, and recover from information security incidents and notify the competent authority of incidents with potential aviation safety impact.
- Incident response plan
- SOC monitoring evidence
- Incident log
- Notifications to competent authority
- No 24x7 detection capability
- Authority notification thresholds undefined
- No post-incident reviews
Report information security incidents and vulnerabilities with potential safety impact to the competent authority within prescribed timeframes.
- External reporting procedure
- Submitted notification records
- Timeline evidence
- Coordination with national CSIRT
- Misses 72 hour or other prescribed deadlines
- No template for authority notification
- No coordination path with national CSIRT
Operations
Protect OT, aircraft systems interfaces, and ground support systems from cyber threats with appropriate segregation.
- Network segmentation diagrams
- OT asset register
- Patch records for OT
- Aircraft data load procedures
- Flat networks between IT and OT
- Unsupported OT software
- Aircraft data loaders not verified
Part-IS.AR: Authority Requirements
Authority establishes oversight programme for Part-IS, including audits, inspections, and follow-up.
- Authority oversight programme
- Inspector qualification records
- Audit plan and reports
- Inspector training not documented
- Risk-based oversight not applied
- Findings closure not tracked
Authorities share information on threats, vulnerabilities, and incidents with relevant aviation organisations and other authorities.
- Information sharing protocols
- Coordination logs with EASA and CSIRTs
- Confidentiality agreements
- No formal channel with national CSIRT
- Threat intelligence not disseminated
- Confidentiality breaches
Process for issuing findings and requiring corrective actions from organisations
- Findings register
- Corrective action plan
- Closure evidence
- Authority correspondence
- Actions not closed within deadline
- Evidence weak
- No root-cause analysis
- Authority correspondence not logged
Authority procedures for responding to reported information security incidents
- Authority IR coordination plan
- Notification SOP
- Evidence preservation procedure
- Joint exercise records
- No coordination plan
- Notifications delayed
- Evidence not preserved
- No joint exercises
Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645)
Establish, implement, and maintain an ISMS to ensure management of information security risks
- ISMS scope statement
- Statement of applicability
- ISMS policy
- Management review minutes
- Scope undefined
- SoA missing
- Policy unapproved
- Reviews skipped
Identify and assess information security risks that could affect aviation safety
- Risk assessment methodology
- Risk register
- Aviation impact mapping
- Annual reassessment
- Aviation safety impact ignored
- Methodology inconsistent
- Register outdated
- Reassessment skipped
Develop and implement measures to treat identified information security risks
- Risk treatment plan
- Control implementation evidence
- Residual risk acceptance
- Effectiveness monitoring
- Treatment plans aspirational
- Implementation slow
- Residual risk not accepted
- Monitoring absent
Ensure staff are competent and aware of information security responsibilities
- Competence framework
- Training records
- Role-based curricula
- Annual refresher schedule
- Competence not assessed
- Curricula generic
- Refreshers missed
- Records incomplete
Establish a continuous process for managing information security risks
- Risk management process documentation
- Lifecycle integration
- KRIs and KPIs
- Annual maturity assessment
- Lifecycle integration weak
- KRIs absent
- Maturity unmeasured
- Process not refreshed
Report significant information security incidents to the competent authority
- External reporting SOP
- Notification timeline tracker
- Submission templates
- Authority correspondence log
- Reporting timelines missed
- Templates absent
- Correspondence not logged
- Triage criteria unclear
Establish an internal reporting scheme for information security events
- Internal reporting policy
- Just culture statement
- Reporting channel
- Anonymised trend report
- Just culture not implemented
- Channel underused
- Trend reports absent
- Policy not communicated
Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203)
Establish and maintain an ISMS proportionate to organizational size and complexity
- ISMS scope statement
- Statement of applicability
- ISMS policy
- Management review minutes
- Scope undefined
- SoA missing
- Policy unapproved
- Reviews skipped
Identify and evaluate information security risks to aviation safety
- Risk assessment methodology
- Risk register
- Aviation impact mapping
- Annual reassessment
- Aviation safety impact ignored
- Methodology inconsistent
- Register outdated
- Reassessment skipped
Implement appropriate measures to treat identified information security risks
- Risk treatment plan
- Control implementation evidence
- Residual risk acceptance
- Effectiveness monitoring
- Treatment plans aspirational
- Implementation slow
- Residual risk not accepted
- Monitoring absent
Ensure personnel competence and awareness in information security
- Competence framework
- Training records
- Role-based curricula
- Annual refresher schedule
- Competence not assessed
- Curricula generic
- Refreshers missed
- Records incomplete
Continuous management of information security risks through structured processes
- Risk management process documentation
- Lifecycle integration
- KRIs and KPIs
- Annual maturity assessment
- Lifecycle integration weak
- KRIs absent
- Maturity unmeasured
- Process not refreshed
Report significant information security incidents to authorities
- External reporting SOP
- Notification timeline tracker
- Submission templates
- Authority correspondence log
- Reporting timelines missed
- Templates absent
- Correspondence not logged
- Triage criteria unclear
Internal collection and analysis of information security events
- Internal reporting policy
- Just culture statement
- Reporting channel
- Anonymised trend report
- Just culture not implemented
- Channel underused
- Trend reports absent
- Policy not communicated
Risk Management
Identify, analyse, and evaluate information security risks that could affect aviation safety, using a documented methodology.
- Risk assessment methodology document
- Asset and threat inventory
- Risk register with impact on safety
- Risk acceptance records
- Risk scoring not tied to safety outcomes
- Assets register incomplete for industrial control systems
- No periodic reassessment
Select and implement risk treatment measures and document residual risk acceptance by accountable management.
- Risk treatment plan
- Statement of applicability
- Residual risk acceptance signed by accountable manager
- Treatment plan lacks owners or dates
- Residual risk acceptance not signed
- No re-evaluation after control changes
Third Party
Where activities are contracted out, ensure responsibility remains with the organisation and the contractor meets Part-IS requirements.
- Contracts with information security clauses
- Supplier oversight reports
- Audit reports of providers
- No flow-down of Part-IS obligations
- No audit right exercised
- Subcontractors not covered
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EASA Part-IS - Information Security in Aviation framework page.