ICAO Annex 17 - Aviation Security (AVSEC)
ICAO Annex 17 Chap 4 - Access Control + Personnel

ICAO Annex 17 - Aviation Security (AVSEC) ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background: ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting

Chapter 4 establishes preventive security measures starting with access control + personnel security. 4.1 Measures Relating to Access Control - each State shall establish + implement measures to prevent unauthorised persons + vehicles + items from gaining access to airside areas + security restricted areas (SRAs); identification of persons authorised to access airside + SRAs through aviation security identification card (ASIC) or equivalent + photo + name + employer + access privilege + expiry + revocation; biometric or PIN access controls for SRAs; vehicle access controls + screening + escort; access boundary protection + perimeter fencing + gates + lighting + CCTV + monitoring + intrusion detection; ramp + boarding bridge + jet bridge + tarmac. 4.2 Measures Relating to Personnel - each State shall ensure that persons implementing security controls are subject to background check before being authorised to access airside or SRAs without escort; background check covers identity + criminal history + employment + financial + reference + residence + intelligence vetting (per national programme); periodic re-investigation + adverse event tracking + insider threat detection + behavioural observation + continuous evaluation; identity verification + ASIC issuance + revocation; visitor + contractor + service supplier escort; cleaner + catering + ground handler + fuel handler personnel access; foreign worker considerations. Coordinates with ICAO Doc 8973 + national intelligence + national vetting authority + EU Reg 2015/1998 + FAA Aviation Worker Vetting + IATA Insider Threat + GASeP PO5 Insider Threat. ICAO Annex 17 Chap 4 + Access Control + Airside + SRA + Personnel + Background + Insider Threat applies.

What else in your programme already covers this

This control maps to 37 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

ISO/IEC 27010:2015 · 3 controls

FDA 21 CFR Part 11 · 2 controls

  • Part11.10 Controls for closed systems (21 CFR §11.10)
  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

ISO/IEC 27011:2024 · 2 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.9 Encrypt Data on Removable Media

OWASP ASVS · 2 controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

FISMA · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP Rev 5 · 1 control

  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

HITECH Act · 1 control

  • 62351-8 Role-based access control (RBAC)
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA

OWASP Top 10:2025 · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.