Chapter 2 establishes the risk-based approach to aviation security. 2.4 Threat Assessment and Risk Management - each Contracting State shall continually monitor and adjust the level of threat for civil aviation within its territory and shall establish and implement policies + procedures + measures to adjust elements of its NCASP accordingly + based on a security risk assessment; threat assessment evaluates intent + capability + targeting + relevance to civil aviation operations + insider threat + cyber + adversary tactics techniques and procedures; vulnerability assessment + consequence analysis + risk treatment + residual risk + monitoring. Coordinated with ICAO Doc 8973 Annex 17 Threat and Risk Methodology + national intelligence + INTERPOL + RAILPOL + WCO. 4.9 Cyber Threats to Critical Aviation Systems (Amendment 17 effective 16 November 2018 + Amendment 18 expansion) - each Contracting State shall ensure that operators or entities defined in NCASP take appropriate measures to identify their critical information and communications technology systems and data used for civil aviation purposes; protect them from cyber attacks per identified risks; coverage of: passenger reservation + departure control + load planning + aircraft communications + air traffic management + navigation + weather + maintenance + crew management + cargo + financial; supply chain cyber risk; cyber-physical convergence; coordination with national CSIRT + intelligence + WCO + IATA cyber framework + EASA Part-IS + FAA cyber rules + IATF EASA + national CSIRT. Coordinates with NIS2 maritime aviation + ENISA Airport Cyber Security + ICAO Doc 8973 Cyber Annex + 2024-2025 pipeline (AI for aviation + supply chain cyber + quantum-resistant crypto + autonomous + drone). ICAO Annex 17 Chap 2 + Threat + Risk + Cyber + GASeP applies.
This control maps to 542 controls across 218 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 542 it maps to, and the evidence behind each claim, over MCP and REST.