EASA Part-IS — Information Security in Aviation
EASA (European Union Aviation Safety Agency) Part-IS (Information Security) regulations establish information security requirements for aviation organizations under the EASA regulatory framework. Part-IS requires organizations to establish an Information Security Management System (ISMS) to protect aviation safety from information security threats. Applies to organizations holding EASA approvals including airlines, maintenance organizations, design organizations, and air traffic management providers. Effective October 2025 (large organizations) and 2026 (smaller entities).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Access Control
| Code | Title |
|---|---|
| IS.I.OR.100 | Access Control to Aviation Information Systems |
Change Management
| Code | Title |
|---|---|
| IS.OR.255 | Changes to the Information Security Management System |
Compliance
| Code | Title |
|---|---|
| IS.OR.225 | Response to Findings Notified by the Competent Authority |
Cryptography
| Code | Title |
|---|---|
| IS.I.OR.110 | Cryptographic Controls |
Documentation
| Code | Title |
|---|---|
| IS.OR.245 | Record-Keeping |
| IS.OR.250 | Information Security Management Manual (ISMM) |
Governance
| Code | Title |
|---|---|
| IS.OR.200 | Information Security Management System (ISMS) |
| IS.OR.260 | Continuous Improvement |
Human Resources
| Code | Title |
|---|---|
| IS.OR.240 | Personnel Requirements |
Incident Management
| Code | Title |
|---|---|
| IS.OR.215 | Information Security Internal Reporting Scheme |
| IS.OR.220 | Information Security Incidents Detection, Response and Recovery |
| IS.OR.230 | Information Security External Reporting |
Operations
| Code | Title |
|---|---|
| IS.I.OR.120 | Operational Technology and Aircraft Systems |
Oversight
| Code | Title |
|---|---|
| IS.AR.200 | Competent Authority Oversight |
| IS.AR.205 | Authority Information Sharing |
Part-IS.AR: Authority Requirements
| Code | Title |
|---|---|
| IS.AR.200 | Competent Authority Oversight |
| IS.AR.205 | Authority Information Sharing |
| IS.AR.210 | Findings and Corrective Actions |
| IS.AR.215 | Information Security Incident Response |
Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645)
| Code | Title |
|---|---|
| IS.D.OR.200 | Information Security Management System |
| IS.D.OR.205 | Information Security Risk Assessment |
| IS.D.OR.210 | Information Security Risk Treatment |
| IS.D.OR.215 | Personnel Requirements |
| IS.D.OR.220 | Information Security Risk Management Process |
| IS.D.OR.225 | External Reporting of Information Security Events |
| IS.D.OR.230 | Internal Reporting Scheme |
Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203)
| Code | Title |
|---|---|
| IS.I.OR.200 | Information Security Management System |
| IS.I.OR.205 | Information Security Risk Assessment |
| IS.I.OR.210 | Information Security Risk Treatment |
| IS.I.OR.215 | Personnel Requirements |
| IS.I.OR.220 | Information Security Risk Management |
| IS.I.OR.225 | External Reporting |
| IS.I.OR.230 | Internal Reporting Scheme |
Risk Management
| Code | Title |
|---|---|
| IS.OR.205 | Information Security Risk Assessment |
| IS.OR.210 | Information Security Risk Treatment |
Third Party
| Code | Title |
|---|---|
| IS.OR.235 | Contracting of Information Security Management Activities |
Your Compliance Coverage
If you comply with EASA Part-IS — Information Security in Aviation, you already cover:
Maps to 517 other frameworks
Frequently Asked Questions
What is EASA Part-IS — Information Security in Aviation?
EASA Part-IS — Information Security in Aviation is a compliance framework from European Union with 15 domains and 36 controls. EASA (European Union Aviation Safety Agency) Part-IS (Information Security) regulations establish information security requirements for aviation organizations under the EASA regulatory framework. Part-IS requires organizations to establish an Information Security Management System (ISMS) to protect aviation safety from information security threats. Applies to organizations holding EASA approvals including airlines, maintenance organizations, design organizations, and air traffic management providers. Effective October 2025 (large organizations) and 2026 (smaller entities). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EASA Part-IS — Information Security in Aviation have?
EASA Part-IS — Information Security in Aviation has 36 controls organised across 15 domains. The largest domains are Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645) (7 controls), Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203) (7 controls), Part-IS.AR: Authority Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EASA Part-IS — Information Security in Aviation map to?
EASA Part-IS — Information Security in Aviation maps to 517 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements (26% coverage), TISAX — Trusted Information Security Assessment Exchange (26% coverage), South Korea ISMS-P (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EASA Part-IS — Information Security in Aviation compliance?
Start your EASA Part-IS — Information Security in Aviation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EASA Part-IS — Information Security in Aviation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required