Skip to content

Evidence request lists

EASA Part-IS - Information Security in Aviation

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

IS.I.OR.100
Access Control to Aviation Information Systems

Implement logical and physical access controls to aviation information systems based on least privilege.

Artefacts an auditor will ask for
  • Access control policy
  • MFA enforcement records
  • Quarterly access reviews
  • Physical access logs to data centres
Where this commonly fails
  • Privileged accounts without MFA
  • Access reviews skipped
  • Shared accounts in operations

Change Management

IS.OR.255
Changes to the Information Security Management System

Manage changes to the ISMS so that compliance and effectiveness are preserved, with prior approval where required by the authority.

Artefacts an auditor will ask for
  • Change management procedure
  • Change records
  • Approval correspondence with authority where applicable
Where this commonly fails
  • Changes implemented without impact assessment
  • Authority not notified of significant changes
  • No rollback plan

Compliance

IS.OR.225
Response to Findings Notified by the Competent Authority

Define corrective actions, implement them, and report progress in response to authority findings.

Artefacts an auditor will ask for
  • Corrective action plan
  • Findings register
  • Closure evidence submitted to authority
Where this commonly fails
  • Root cause analysis absent
  • Actions not tracked to closure
  • Late submission to authority

Cryptography

IS.I.OR.110
Cryptographic Controls

Apply cryptographic controls to protect aviation data in transit and at rest, with managed key lifecycle.

Artefacts an auditor will ask for
  • Cryptography policy
  • Key management procedures
  • TLS configuration scans
  • HSM evidence
Where this commonly fails
  • Deprecated TLS versions in use
  • Keys never rotated
  • No HSM for high-impact keys

Documentation

IS.OR.245
Record-Keeping

Maintain records of ISMS activities, risk assessments, incidents, training, and audits for the periods defined by the authority.

Artefacts an auditor will ask for
  • Records retention schedule
  • Audit logs of record access
  • Sample records covering retention period
Where this commonly fails
  • Retention periods inconsistent with authority requirements
  • Records not tamper evident
  • No retrieval test
IS.OR.250
Information Security Management Manual (ISMM)

Produce and maintain an Information Security Management Manual describing how the organisation complies with Part-IS.

Artefacts an auditor will ask for
  • Current ISMM
  • Approval and revision history
  • Distribution list
  • Cross-reference to Part-IS requirements
Where this commonly fails
  • ISMM lacks cross-reference matrix
  • Out of date sections
  • Not linked to safety management manual

Governance

IS.OR.200
Information Security Management System (ISMS)

Establish, implement, and maintain an ISMS proportionate to the organisation's nature, size, and information security risks affecting aviation safety.

Artefacts an auditor will ask for
  • ISMS charter
  • Scope statement covering aviation activities
  • Approved information security policy
  • Management review minutes
Where this commonly fails
  • ISMS scope omits OT or maintenance systems
  • No board-level approval
  • Policy not aligned with safety management system
IS.OR.260
Continuous Improvement

Continually improve the effectiveness of the ISMS based on audits, reviews, incidents, and changing threats.

Artefacts an auditor will ask for
  • Management review minutes
  • KPI dashboard
  • Lessons learned register
  • Improvement plan
Where this commonly fails
  • No measurable KPIs
  • Management review skipped
  • Lessons learned not actioned

Human Resources

IS.OR.240
Personnel Requirements

Ensure personnel are competent for their information security responsibilities and have appropriate authority.

Artefacts an auditor will ask for
  • Role descriptions including IS duties
  • Competency matrix
  • Training plan
  • Background checks where applicable
Where this commonly fails
  • No competency definition for ISMS lead
  • Training not aviation-specific
  • Background screening absent for sensitive roles

Incident Management

IS.OR.215
Information Security Internal Reporting Scheme

Operate an internal scheme for staff and contractors to report information security events that may affect aviation safety.

Artefacts an auditor will ask for
  • Internal reporting procedure
  • Just culture policy
  • Reporting metrics
  • Training records for personnel
Where this commonly fails
  • No anonymous channel
  • Reports not triaged within defined SLA
  • Personnel unaware of duty to report
IS.OR.220
Information Security Incidents Detection, Response and Recovery

Detect, respond to, and recover from information security incidents and notify the competent authority of incidents with potential aviation safety impact.

Artefacts an auditor will ask for
  • Incident response plan
  • SOC monitoring evidence
  • Incident log
  • Notifications to competent authority
Where this commonly fails
  • No 24x7 detection capability
  • Authority notification thresholds undefined
  • No post-incident reviews
IS.OR.230
Information Security External Reporting

Report information security incidents and vulnerabilities with potential safety impact to the competent authority within prescribed timeframes.

Artefacts an auditor will ask for
  • External reporting procedure
  • Submitted notification records
  • Timeline evidence
  • Coordination with national CSIRT
Where this commonly fails
  • Misses 72 hour or other prescribed deadlines
  • No template for authority notification
  • No coordination path with national CSIRT

Operations

IS.I.OR.120
Operational Technology and Aircraft Systems

Protect OT, aircraft systems interfaces, and ground support systems from cyber threats with appropriate segregation.

Artefacts an auditor will ask for
  • Network segmentation diagrams
  • OT asset register
  • Patch records for OT
  • Aircraft data load procedures
Where this commonly fails
  • Flat networks between IT and OT
  • Unsupported OT software
  • Aircraft data loaders not verified

Part-IS.AR: Authority Requirements

IS.AR.200
Competent Authority Oversight

Authority establishes oversight programme for Part-IS, including audits, inspections, and follow-up.

Artefacts an auditor will ask for
  • Authority oversight programme
  • Inspector qualification records
  • Audit plan and reports
Where this commonly fails
  • Inspector training not documented
  • Risk-based oversight not applied
  • Findings closure not tracked
IS.AR.205
Authority Information Sharing

Authorities share information on threats, vulnerabilities, and incidents with relevant aviation organisations and other authorities.

Artefacts an auditor will ask for
  • Information sharing protocols
  • Coordination logs with EASA and CSIRTs
  • Confidentiality agreements
Where this commonly fails
  • No formal channel with national CSIRT
  • Threat intelligence not disseminated
  • Confidentiality breaches
IS.AR.210
Findings and Corrective Actions

Process for issuing findings and requiring corrective actions from organisations

Artefacts an auditor will ask for
  • Findings register
  • Corrective action plan
  • Closure evidence
  • Authority correspondence
Where this commonly fails
  • Actions not closed within deadline
  • Evidence weak
  • No root-cause analysis
  • Authority correspondence not logged
IS.AR.215
Information Security Incident Response

Authority procedures for responding to reported information security incidents

Artefacts an auditor will ask for
  • Authority IR coordination plan
  • Notification SOP
  • Evidence preservation procedure
  • Joint exercise records
Where this commonly fails
  • No coordination plan
  • Notifications delayed
  • Evidence not preserved
  • No joint exercises

Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645)

IS.D.OR.200
Information Security Management System

Establish, implement, and maintain an ISMS to ensure management of information security risks

Artefacts an auditor will ask for
  • ISMS scope statement
  • Statement of applicability
  • ISMS policy
  • Management review minutes
Where this commonly fails
  • Scope undefined
  • SoA missing
  • Policy unapproved
  • Reviews skipped
IS.D.OR.205
Information Security Risk Assessment

Identify and assess information security risks that could affect aviation safety

Artefacts an auditor will ask for
  • Risk assessment methodology
  • Risk register
  • Aviation impact mapping
  • Annual reassessment
Where this commonly fails
  • Aviation safety impact ignored
  • Methodology inconsistent
  • Register outdated
  • Reassessment skipped
IS.D.OR.210
Information Security Risk Treatment

Develop and implement measures to treat identified information security risks

Artefacts an auditor will ask for
  • Risk treatment plan
  • Control implementation evidence
  • Residual risk acceptance
  • Effectiveness monitoring
Where this commonly fails
  • Treatment plans aspirational
  • Implementation slow
  • Residual risk not accepted
  • Monitoring absent
IS.D.OR.215
Personnel Requirements

Ensure staff are competent and aware of information security responsibilities

Artefacts an auditor will ask for
  • Competence framework
  • Training records
  • Role-based curricula
  • Annual refresher schedule
Where this commonly fails
  • Competence not assessed
  • Curricula generic
  • Refreshers missed
  • Records incomplete
IS.D.OR.220
Information Security Risk Management Process

Establish a continuous process for managing information security risks

Artefacts an auditor will ask for
  • Risk management process documentation
  • Lifecycle integration
  • KRIs and KPIs
  • Annual maturity assessment
Where this commonly fails
  • Lifecycle integration weak
  • KRIs absent
  • Maturity unmeasured
  • Process not refreshed
IS.D.OR.225
External Reporting of Information Security Events

Report significant information security incidents to the competent authority

Artefacts an auditor will ask for
  • External reporting SOP
  • Notification timeline tracker
  • Submission templates
  • Authority correspondence log
Where this commonly fails
  • Reporting timelines missed
  • Templates absent
  • Correspondence not logged
  • Triage criteria unclear
IS.D.OR.230
Internal Reporting Scheme

Establish an internal reporting scheme for information security events

Artefacts an auditor will ask for
  • Internal reporting policy
  • Just culture statement
  • Reporting channel
  • Anonymised trend report
Where this commonly fails
  • Just culture not implemented
  • Channel underused
  • Trend reports absent
  • Policy not communicated

Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203)

IS.I.OR.200
Information Security Management System

Establish and maintain an ISMS proportionate to organizational size and complexity

Artefacts an auditor will ask for
  • ISMS scope statement
  • Statement of applicability
  • ISMS policy
  • Management review minutes
Where this commonly fails
  • Scope undefined
  • SoA missing
  • Policy unapproved
  • Reviews skipped
IS.I.OR.205
Information Security Risk Assessment

Identify and evaluate information security risks to aviation safety

Artefacts an auditor will ask for
  • Risk assessment methodology
  • Risk register
  • Aviation impact mapping
  • Annual reassessment
Where this commonly fails
  • Aviation safety impact ignored
  • Methodology inconsistent
  • Register outdated
  • Reassessment skipped
IS.I.OR.210
Information Security Risk Treatment

Implement appropriate measures to treat identified information security risks

Artefacts an auditor will ask for
  • Risk treatment plan
  • Control implementation evidence
  • Residual risk acceptance
  • Effectiveness monitoring
Where this commonly fails
  • Treatment plans aspirational
  • Implementation slow
  • Residual risk not accepted
  • Monitoring absent
IS.I.OR.215
Personnel Requirements

Ensure personnel competence and awareness in information security

Artefacts an auditor will ask for
  • Competence framework
  • Training records
  • Role-based curricula
  • Annual refresher schedule
Where this commonly fails
  • Competence not assessed
  • Curricula generic
  • Refreshers missed
  • Records incomplete
IS.I.OR.220
Information Security Risk Management

Continuous management of information security risks through structured processes

Artefacts an auditor will ask for
  • Risk management process documentation
  • Lifecycle integration
  • KRIs and KPIs
  • Annual maturity assessment
Where this commonly fails
  • Lifecycle integration weak
  • KRIs absent
  • Maturity unmeasured
  • Process not refreshed
IS.I.OR.225
External Reporting

Report significant information security incidents to authorities

Artefacts an auditor will ask for
  • External reporting SOP
  • Notification timeline tracker
  • Submission templates
  • Authority correspondence log
Where this commonly fails
  • Reporting timelines missed
  • Templates absent
  • Correspondence not logged
  • Triage criteria unclear
IS.I.OR.230
Internal Reporting Scheme

Internal collection and analysis of information security events

Artefacts an auditor will ask for
  • Internal reporting policy
  • Just culture statement
  • Reporting channel
  • Anonymised trend report
Where this commonly fails
  • Just culture not implemented
  • Channel underused
  • Trend reports absent
  • Policy not communicated

Risk Management

IS.OR.205
Information Security Risk Assessment

Identify, analyse, and evaluate information security risks that could affect aviation safety, using a documented methodology.

Artefacts an auditor will ask for
  • Risk assessment methodology document
  • Asset and threat inventory
  • Risk register with impact on safety
  • Risk acceptance records
Where this commonly fails
  • Risk scoring not tied to safety outcomes
  • Assets register incomplete for industrial control systems
  • No periodic reassessment
IS.OR.210
Information Security Risk Treatment

Select and implement risk treatment measures and document residual risk acceptance by accountable management.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Statement of applicability
  • Residual risk acceptance signed by accountable manager
Where this commonly fails
  • Treatment plan lacks owners or dates
  • Residual risk acceptance not signed
  • No re-evaluation after control changes

Third Party

IS.OR.235
Contracting of Information Security Management Activities

Where activities are contracted out, ensure responsibility remains with the organisation and the contractor meets Part-IS requirements.

Artefacts an auditor will ask for
  • Contracts with information security clauses
  • Supplier oversight reports
  • Audit reports of providers
Where this commonly fails
  • No flow-down of Part-IS obligations
  • No audit right exercised
  • Subcontractors not covered
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EASA Part-IS - Information Security in Aviation framework page.