EASA Part-IS - Information Security in Aviation
EASA (European Union Aviation Safety Agency) Part‑IS (Information Security) regulation establishes mandatory information security requirements for aviation organisations. It requires the implementation of an Information Security Management System (ISMS) aligned with ISO/IEC 27001, covering 15 security domains and 34 controls, to protect the confidentiality, integrity and availability of aviation‑related information. The regulation (Commission Regulation (EU) 2022/xxxx) becomes fully effective in 2025.
EASA Part-IS - Information Security in Aviation is a compliance framework from European Union with 14 domains and 34 controls that map to 210 other frameworks. The largest domains are Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645) (7 controls), Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203) (7 controls), Part-IS.AR: Authority Requirements (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
Access Control
| Code | Title |
|---|---|
| IS.I.OR.100 | Access Control to Aviation Information Systems |
Change Management
| Code | Title |
|---|---|
| IS.OR.255 | Changes to the Information Security Management System |
Compliance
| Code | Title |
|---|---|
| IS.OR.225 | Response to Findings Notified by the Competent Authority |
Cryptography
| Code | Title |
|---|---|
| IS.I.OR.110 | Cryptographic Controls |
Documentation
Governance
Human Resources
| Code | Title |
|---|---|
| IS.OR.240 | Personnel Requirements |
Incident Management
Operations
| Code | Title |
|---|---|
| IS.I.OR.120 | Operational Technology and Aircraft Systems |
Part-IS.AR: Authority Requirements
Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645)
| Code | Title |
|---|---|
| IS.D.OR.200 | Information Security Management System |
| IS.D.OR.205 | Information Security Risk Assessment |
| IS.D.OR.210 | Information Security Risk Treatment |
| IS.D.OR.215 | Personnel Requirements |
| IS.D.OR.220 | Information Security Risk Management Process |
| IS.D.OR.225 | External Reporting of Information Security Events |
| IS.D.OR.230 | Internal Reporting Scheme |
Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203)
| Code | Title |
|---|---|
| IS.I.OR.200 | Information Security Management System |
| IS.I.OR.205 | Information Security Risk Assessment |
| IS.I.OR.210 | Information Security Risk Treatment |
| IS.I.OR.215 | Personnel Requirements |
| IS.I.OR.220 | Information Security Risk Management |
| IS.I.OR.225 | External Reporting |
| IS.I.OR.230 | Internal Reporting Scheme |
Risk Management
Third Party
| Code | Title |
|---|---|
| IS.OR.235 | Contracting of Information Security Management Activities |
Your Compliance Coverage
If you comply with EASA Part-IS - Information Security in Aviation, you already cover:
ISO 27701:2019
32%
11 controls mapped
Compare →NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
26%
9 controls mapped
Compare →South Korea ISMS-P
26%
9 controls mapped
Compare →+ 207 more: NRF Cybersecurity and Data Privacy Framework (National Retail Federation) (24%), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (24%)
See all 210 mapped frameworks ↓Maps to 210 other frameworks
What is EASA Part-IS - Information Security in Aviation and who does it apply to?
EASA Part-IS - Information Security in Aviation is a compliance framework from European Union with 14 domains and 34 controls. EASA (European Union Aviation Safety Agency) Part‑IS (Information Security) regulation establishes mandatory information security requirements for aviation organisations. It requires the implementation of an Information Security Management System (ISMS) aligned with ISO/IEC 27001, covering 15 security domains and 34 controls, to protect the confidentiality, integrity and availability of aviation‑related information. The regulation (Commission Regulation (EU) 2022/xxxx) becomes fully effective in 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EASA Part-IS - Information Security in Aviation actually require?
EASA Part-IS - Information Security in Aviation has 34 controls organised across 14 domains. The largest domains are Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645) (7 controls), Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203) (7 controls), Part-IS.AR: Authority Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EASA Part-IS - Information Security in Aviation do I already cover?
EASA Part-IS - Information Security in Aviation maps to 210 other compliance frameworks. The top mapping partners are ISO 27701:2019 (32% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (26% coverage), South Korea ISMS-P (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EASA Part-IS - Information Security in Aviation?
Start your EASA Part-IS - Information Security in Aviation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EASA Part-IS - Information Security in Aviation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required