ICAO Annex 17 - Aviation Security (AVSEC)
ICAO Annex 17 Chap 2 - Threat + Risk + Cyber

ICAO Annex 17 - Aviation Security (AVSEC) ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP: ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)

Chapter 2 establishes the risk-based approach to aviation security. 2.4 Threat Assessment and Risk Management - each Contracting State shall continually monitor and adjust the level of threat for civil aviation within its territory and shall establish and implement policies + procedures + measures to adjust elements of its NCASP accordingly + based on a security risk assessment; threat assessment evaluates intent + capability + targeting + relevance to civil aviation operations + insider threat + cyber + adversary tactics techniques and procedures; vulnerability assessment + consequence analysis + risk treatment + residual risk + monitoring. Coordinated with ICAO Doc 8973 Annex 17 Threat and Risk Methodology + national intelligence + INTERPOL + RAILPOL + WCO. 4.9 Cyber Threats to Critical Aviation Systems (Amendment 17 effective 16 November 2018 + Amendment 18 expansion) - each Contracting State shall ensure that operators or entities defined in NCASP take appropriate measures to identify their critical information and communications technology systems and data used for civil aviation purposes; protect them from cyber attacks per identified risks; coverage of: passenger reservation + departure control + load planning + aircraft communications + air traffic management + navigation + weather + maintenance + crew management + cargo + financial; supply chain cyber risk; cyber-physical convergence; coordination with national CSIRT + intelligence + WCO + IATA cyber framework + EASA Part-IS + FAA cyber rules + IATF EASA + national CSIRT. Coordinates with NIS2 maritime aviation + ENISA Airport Cyber Security + ICAO Doc 8973 Cyber Annex + 2024-2025 pipeline (AI for aviation + supply chain cyber + quantum-resistant crypto + autonomous + drone). ICAO Annex 17 Chap 2 + Threat + Risk + Cyber + GASeP applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 542 controls across 218 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

BSI IT-Grundschutz · 6 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO 27005 · 6 controls

ISO 31000 · 6 controls

ISO/IEC 23894:2023 · 6 controls

NIST SP 800-30 · 6 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

API 1164 · 5 controls

IEC 62443 · 5 controls

ISO 27019 · 5 controls

MARS-E · 5 controls

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

NIST SP 1800-32 · 5 controls

  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

ISO 13485 · 4 controls

ISO 27799 · 4 controls

Japan AI Guidelines · 4 controls

MDS2 (Medical Device) · 4 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-37 · 4 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-66 · 4 controls

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

SASB Standards · 4 controls

South Korea ISMS-P · 4 controls

  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

IEEE 1686 · 3 controls

ISO 27043 · 3 controls

ISO/IEC 27003:2017 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/SAE 21434 · 3 controls

NIST SP 800-39 · 3 controls

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

Solvency II · 3 controls

  • CH-FADP-15 Cooperation with the FDPIC
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • SPS220-28 Annual Board Risk Management Declaration
  • P1-S1 Advance Electronic Information
  • P1-S2 Risk-Management Systems

Bahrain PDPL · 2 controls

  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

IEEE 7000 · 2 controls

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

ISO/IEC 27014:2020 · 2 controls

India DPDP Act · 2 controls

Indonesia PDP Law · 2 controls

LGPD · 2 controls

Liechtenstein DPA · 2 controls

MITRE ATT&CK · 2 controls

Malaysia PDPA 2010 · 2 controls

Mauritius DPA · 2 controls

Mexico LFPDPPP · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4

NERC CIP · 2 controls

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NERCCIP-8 Supply Chain Risk Management (CIP-013)
  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities
  • NIS2I-6 Access Control, Asset Management, and Physical Security

NIST SP 800-122 · 2 controls

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud

OWASP ASVS · 2 controls

  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • ORSA-S2 ORSA Manual Section 2: Insurer's Assessment of Risk Exposure
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process

PDPA Singapore · 2 controls

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection

POPIA · 2 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 2 controls

  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

Saudi Arabia PDPL · 2 controls

  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Turkey KVKK · 2 controls

Vietnam PDPD · 2 controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • 4.3.1 Risk Assessment and Impact Analysis
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • FAA-CSA-International Coordination with EASA Part-IS, ICAO AVSEC and International Cybersecurity Frameworks

FedRAMP High · 1 control

  • RA-1 Policy and Procedures

FedRAMP Moderate · 1 control

  • RA-1 Policy and Procedures

GDPR · 1 control

  • 62351-8 Role-based access control (RBAC)

ISMAP (Japan) · 1 control

ISO 20000-1 · 1 control

ISO 22000 · 1 control

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 45001 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ITIL 4 · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework

NIST SP 800-190 · 1 control

  • RA-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • RA-1 Policy and Procedures

NIST SP 800-61 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

OWASP Top 10:2025 · 1 control

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management

PTES · 1 control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration

SOC 2 · 1 control

  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

Taiwan PDPA · 1 control

  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKOPRES-3 Self-Assessment and Board Engagement
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 542 it maps to, and the evidence behind each claim, over MCP and REST.