Part-IS Shop-Floor Practice and Reporting
Personal rules, a phishing check, controls for maintenance, CAMO and operations, and what to do when you suspect an incident.
Dionysis Kefalas9 min readFor Part-145, CAMO and Air Ops staff
Part 4 of 4 in Part-IS Implementation Show parts
- 1Part-IS Requirements, Scope and Deadlines
- 2Aviation Information Security, Explained
- 3Aviation Cyber Incidents and Their Lessons
- 4Part-IS Shop-Floor Practice and Reporting
Quotes checked on against EASA Easy Access Rules for Information Security (Regulations (EU) 2022/1645 and (EU) 2023/203) — 5 Dec 2025 revision.
On this page
Personal rules
The question at the bench is what to do differently. These personal rules each break a link in the attack chains from the previous guides:
- Use strong, unique passwords — and MFA everywhere it is offered. A password manager beats memory. One password per account; multi-factor authentication turns a stolen password into a dead end.
- Think before you click. Check the real sender address, hover over links before opening them, and treat every unexpected attachment as hostile — especially ones that ask you to 'enable content' or act urgently.
- Verify out-of-band. Bank-detail change? Urgent payment? Unusual request from the boss? Confirm by phone on a number you already have — never via the same email thread.
- Lock your screen, clear your desk. Win+L takes one second. Certificates, passwords and customer data should never sit readable on an unattended desk or screen.
- Control removable media. Only organisation-issued, scanned USB sticks touch work machines — and nothing found in the car park, ever.
- Keep software updated. Install updates promptly on everything you control, and report anything that cannot be updated so it can be isolated and risk-assessed instead of forgotten.
- Use only what you need. Least privilege: no shared logins, no borrowed accounts, no admin rights for daily work. Access that is not needed is risk without benefit.
- Keep work and private separate. No work credentials or documents on private devices and webmail; no personal browsing or charging of private phones on work or bench equipment.
- Be careful on public networks. Airport and hotel Wi-Fi are hostile until proven otherwise — use the company VPN, or your phone's hotspot instead.
- Report immediately — speed beats embarrassment. Clicked something? Saw something odd? Report it through the internal scheme at once. Minutes matter for containment, and the organisation's 72-hour clock depends on you.
The last rule is the one that connects a person at the bench to the reporting rules. The rest of this guide is that connection.
The phishing check
Before acting on any message that asks you to click, open, pay or change something, check it against these red flags:
- Pressure and urgency: 'immediately', 'final notice', 'your account will be closed'.
- Sender domain almost right: example-oem-support.com instead of example-oem.com.
- Generic greeting, unusual tone, or a request that bypasses normal procedure.
- Unexpected attachment, or a link whose real target (hover!) does not match the text.
- Requests for credentials, payments, or changes to bank details.
- When in doubt: do not click, do not reply — verify by phone and report it.
No single flag is proof. Any one of them is reason enough to slow down. The ExampleMRO chain in the previous guide is what a missed check turns into.
Controls that matter in your sector
The ten rules are personal and universal. The controls below are organisational and sectoral — the measures a Part-IS risk assessment will keep surfacing because they sit exactly where an information-security failure turns into an airworthiness or operational problem.
Maintenance (Part-145)
- Segregate bench and test equipment from the office network (separate segment or air-gapped). A phished office laptop is kept off the machines that drive testing and inspection.
- Software and test-data updates for tooling come only from verified OEM sources, via controlled media — never from an email attachment.
- Protect the integrity of test and inspection records. They are the evidence behind every release the organisation issues: controlled access, audit trails, and backups that ransomware cannot reach.
- Treat OEM portal credentials (CMM access, service bulletins) as certification-critical: unique per person, MFA on, never shared.
- Verify the authenticity of incoming certificates. A perfect-looking PDF is not evidence by itself when the email channel it arrived through may be compromised.
Continuing airworthiness (CAMO)
- Protect the integrity and availability of the airworthiness-records system — AD status, fleet records, ARC working files. A review cannot be completed on evidence that has been altered or encrypted.
- Contracted-maintenance interfaces are part of the risk assessment. Control third-party access to records and portals; a contractor's compromise becomes the CAMO's problem at the moment of connection.
- Keep backups of records offline or otherwise unreachable by ransomware — a backup on the same network is just another file to encrypt.
Operations
- Availability of flight-planning, weight-and-balance and crew-records systems is an operational-safety matter, not an IT inconvenience — plan for how the operation continues, and how data integrity is re-verified, if they go down.
- Verify out-of-band any emailed change affecting operational data — fuel figures, load sheets, crew records, supplier details. The same rule as for bank details, for the same reason.
- Public-Wi-Fi discipline for EFBs and crew devices: airport and hotel networks are hostile until proven otherwise — company VPN or a phone hotspot, never the open network.
The internal scheme is what makes the 72 hours possible
The external clock is IS.I.OR.230.
[…]
(b)Without prejudice to the obligations of Regulation (EU) 376/2014, the organisation shall ensure that any information security incident or vulnerability, which may represent a significant risk to aviation safety, is reported to their competent authority. Furthermore:
(1)Where such an incident or vulnerability affects an aircraft or associated system or component, the organisation shall also report it to the design approval holder;
(2)Where such an incident or vulnerability affects a system or constituent used by the organisation, the organisation shall report it to the organisation responsible for the design of the system or constituent.
(c)The organisation shall report the conditions referred to in point (b) as follows:
(1)a notification shall be submitted to the competent authority and, if applicable, to the design approval holder or to the organisation responsible for the design of the system or constituent, as soon as the condition has been known to the organisation;
(2)a report shall be submitted to the competent authority and, if applicable, to the design approval holder or to the organisation responsible for the design of the system or constituent, as soon as possible, but not exceeding 72 hours from the time the condition has been known to the organisation, unless exceptional circumstances prevent this.
The report shall be made in the form defined by the competent authority and shall contain all relevant information about the condition known to the organisation;
(3)a follow-up report shall be submitted to the competent authority and, if applicable, to the design approval holder or to the organisation responsible for the design of the system or constituent, providing details of the actions the organisation has taken or intends to take to recover from the incident and the actions it intends to take to prevent similar information security incidents in the future.
The follow-up report shall be submitted as soon as those actions have been identified, and shall be produced in the form defined by the competent authority.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Point (b) is who is told. Point (c) is the notification, the report and the follow-up. The time limit is in point (c)(2). It does not run from a click that nobody has reported. The internal scheme is how a person's observation becomes something the organisation can know.
(a)The organisation shall establish an internal reporting scheme to enable the collection and evaluation of information security events, including those to be reported pursuant to point IS.I.OR.230.
(b)That scheme and the process referred to in point IS.I.OR.220 shall enable the organisation to:
(1)identify which of the events reported pursuant to point (a) are considered information security incidents or vulnerabilities with a potential impact on aviation safety;
(2)identify the causes of, and contributing factors to, the information security incidents and vulnerabilities identified in accordance with point (1), and address them as part of the information security risk management process in accordance with points IS.I.OR.205 and IS.I.OR.220;
(3)ensure an evaluation of all known, relevant information relating to the information security incidents and vulnerabilities identified in accordance with point (1);
(4)ensure the implementation of a method to distribute internally the information as necessary.
(c)Any contracted organisation which may expose the organisation to information security risks with a potential impact on aviation safety shall be required to report information security events to the organisation. Those reports shall be submitted using the procedures established in the specific contractual arrangements and shall be evaluated in accordance with point (b).
[…]
(e)The organisation may integrate that reporting scheme with other reporting schemes it has already implemented.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Point (a) is what the scheme collects. Point (b) is what the organisation does with those reports. Point (c) is the contracted organisation. Point (e) allows the scheme to sit inside reporting schemes the organisation already runs. The tests are in the quote.
The first guide in this series quotes the whole of IS.I.OR.230, including the point this page skips at the start of the quote above.
If you suspect an incident — do and do not
Everything above is prevention. This last section is for the moment prevention has already failed: you clicked, you saw something odd, a machine is behaving strangely. What you do next decides how hard the recovery is.
Do
- Disconnect the machine from the network — pull the cable, disable Wi-Fi. Containment first.
- Report immediately via the internal reporting scheme (IS.I.OR.215) — by phone or in person if email itself may be affected.
- Write down what you saw, clicked and when. A few honest lines shorten the investigation by hours.
- Change exposed passwords from a different, clean device — never from the machine you suspect.
Do not
- Do not switch the machine off or delete anything. Evidence is lost and recovery gets harder — memory-resident traces of the attack die with the power.
- Do not 'wait and see' or try to fix it quietly yourself. The reporting clock does not pause for embarrassment.
- Do not forward the suspicious email around the office to ask opinions — that multiplies the number of people one click away from infection.
- Do not sit on it. Waiting does not make the condition smaller. Report it through the internal scheme.
Point IS.I.OR.240 is the personnel rule. The points that match the work on this page are these.
[…]
(f)The organisation shall have a process in place to ensure that they have sufficient personnel on duty to carry out the activities covered by this Annex.
(g)The organisation shall have a process in place to ensure that the personnel referred to in point (f) have the necessary competence to perform their tasks.
(h)The organisation shall have a process in place to ensure that personnel acknowledge the responsibilities associated with the assigned roles and tasks.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Points (f), (g) and (h) are the processes for how many people are on duty, whether they can do the work, and whether they have acknowledged the role. The quote does not use the word train.
Educational content, not regulatory compliance advice. Verify against the current regulation text before relying on it.
In this series
Related
Written by Dionysis Kefalas. Retired Hellenic Air Force Captain and founder of Avioverse. About the author
Metis opens with Avioverse in October 2026 · request early access.