ANNEX — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.D.OR]
Delegated Regulation (EU) 2022/1645 · Information Security (Part-IS) · Regulations (EU) 2023/203 and 2022/1645 · IS.D.OR.100 – IS.D.OR.260
On this page
IS.D.OR.100 Scope
This Part establishes the requirements to be met by the organisations referred to in Article 2 of this Regulation.
IS.D.OR.200 Information security management system (ISMS)
In order to achieve the objectives set out in Article 1, the organisation shall set up, implement and maintain an information security management system…
GM1 IS.D.OR.200 Information security management system (ISMS)
AMC1 IS.D.OR.200(a)(1) Information security management system (ISMS)
GM1 IS.D.OR.200(a)(1) Information security management system (ISMS)
AMC1 IS.D.OR.200(a)(12) Information security management system (ISMS)
GM1 IS.D.OR.200(a)(12) Information security management system (ISMS)
AMC1 IS.D.OR.200(a)(13) Information security management system (ISMS)
AMC1 IS.D.OR.200(c) Information security management system (ISMS)
GM1 IS.D.OR.200(c) Information security management system (ISMS)
GM1 IS.D.OR.200(d) Information security management system (ISMS)
AMC1 IS.D.OR.200(e) Information security management system (ISMS)
GM1 IS.D.OR.200(e) Information security management system (ISMS)
IS.D.OR.205 Information security risk assessment
The organisation shall identify all of its elements, which could be exposed to information security risks.
GM1 IS.D.OR.205 Information security risk assessment
AMC1 IS.D.OR.205(a) Information security risk assessment
GM1 IS.D.OR.205(a) Information security risk assessment
AMC1 IS.D.OR.205(b) Information security risk assessment
GM1 IS.D.OR.205(b) Information security risk assessment
GM2 IS.D.OR.205(b) Information security risk assessment
AMC1 IS.D.OR.205(c) Information security risk assessment
GM1 IS.D.OR.205(c) Information security risk assessment
AMC1 IS.D.OR.205(d) Information security risk assessment
IS.D.OR.210 Information security risk treatment
The organisation shall develop measures to address unacceptable risks identified in accordance with point IS.D.OR.205, implement them in a timely manner…
IS.D.OR.215 Information security internal reporting scheme
The organisation shall establish an internal reporting scheme to enable the collection and evaluation of information security events, including those to…
AMC1 IS.D.OR.215(a) &(b) Information security internal reporting scheme
GM1 IS.D.OR.215(a) &(b) Information security internal reporting scheme
GM2 IS.D.OR.215(a) &(b) Information security internal reporting scheme
GM1 IS.D.OR.215(c) Information security internal reporting scheme
GM1 IS.D.OR.215(d) Information security internal reporting scheme
GM3 IS.D.OR 215(a)&(b) Information security internal reporting scheme
RELEVANT INFORMATION FOR INCIDENTS AND VULNERABILITIES Understanding the causes of, and contributing factors to, information security incidents and…
IS.D.OR.220 Information security incidents — detection, response and recovery
Based on the outcome of the risk assessment carried out in accordance with point IS.D.OR.205 and the outcome of the risk treatment performed in…
GM1 IS.D.OR.220 Information security incidents — detection, response and recovery
AMC1 IS.D.OR.220(a) Information security incidents — detection, response and recovery
GM1 IS.D.OR.220(a) Information security incidents — detection, response and recovery
AMC1 IS.D.OR.220(b) Information security incidents — detection, response and recovery
GM1 IS.D.OR.220(b) Information security incidents — detection, response and recovery
AMC1 IS.D.OR.220(c) Information security incidents — detection, response and recovery
GM1 IS.D.OR.220(b) &(c) Information security incidents — detection, response and recovery
GM1 IS.D.OR.220(c) Information security incidents — detection, response and recovery
IS.D.OR.225 Response to findings notified by the competent authority
After receipt of the notification of findings submitted by the competent authority, the organisation shall:
AMC1 IS.D.OR.225 Response to findings notified by the competent authority
GM1 IS.D.OR.225 Response to findings notified by the competent authority
IS.D.OR.230 Information security external reporting scheme
The organisation shall implement an information security reporting system that complies with the requirements laid down in Regulation (EU) No 376/2014…
GM1 IS.D.OR.230 Information security external reporting scheme
AMC1 IS.D.OR.230(a) &(b) Information security external reporting scheme
GM1 IS.D.OR.230(a) &(b) Information security external reporting scheme
AMC1 IS.D.OR.230(c) Information security external reporting scheme
GM1 IS.D.OR.230(c) Information security external reporting scheme
IS.D.OR.235 Contracting of information security management activities
The organisation shall ensure that when contracting any part of the activities referred to in point IS.D.OR.200 to other organisations, the contracted…
GM1 IS.D.OR.235 Contracting of information security management activities
GM2 IS.D.OR.235 Contracting of information security management activities
GM3 IS.D.OR.235 Contracting of information security management activities
GM1 IS.D.OR.235(a) Contracting of information security management activities
AMC1 IS.D.OR.235(a) Contracting of information security management activities
GM2 IS.D.OR.235(a) Contracting of information security management activities
AMC1 IS.D.OR.235(b) Contracting of information security management activities
GM1 IS.D.OR.235(b) Contracting of information security management activities
IS.D.OR.240 Personnel requirements
The accountable manager of the organisation or, in the case of design organisations, the head of the design organisation, designated in accordance with…
GM1 IS.D.OR.240 Personnel requirements
AMC1 IS.D.OR.240(a)(2) Personnel requirements
AMC1 IS.D.OR.240(a)(3) Personnel requirements
GM1 IS.D.OR.240(a)(3) Personnel requirements
AMC1 IS.D.OR.240(b) Personnel requirements
GM1 IS.D.OR.240(b) Personnel requirements
GM1 IS.D.OR.240(b) &(c) Personnel requirements
GM1 IS.D.OR.240(c) Personnel requirements
AMC1 IS.D.OR.240(d) Personnel requirements
GM1 IS.D.OR.240(e) Personnel requirements
AMC1 IS.D.OR.240(f) Personnel requirements
GM1 IS.D.OR.240(f) Personnel requirements
AMC1 IS.D.OR.240(g) Personnel requirements
GM1 IS.D.OR.240(g) Personnel requirements
AMC1 IS.D.OR.240(h) Personnel requirements
GM1 IS.D.OR.240(h) Personnel requirements
IS.D.OR.245 Record-keeping
The organisation shall keep records of its information security management activities (1) The organisation shall ensure that the following records are…
GM1 IS.D.OR.245 Record-keeping
AMC1 IS.D.OR.245(a)(1)(vi) &(a)(5) Record-keeping
GM1 IS.D.OR.245(a)(1)(vi) &(a)(5) Record-keeping
IS.D.OR.250 Information security management manual (ISMM)
The organisation shall make available to the competent authority an information security management manual (ISMM) and, where applicable, any referenced…
GM1 IS.D.OR.250(a) Information security management manual (ISMM)
IS.D.OR.255 Changes to the information security management system
Changes to the ISMS may be managed and notified to the competent authority in a procedure developed by the organisation.
AMC1 IS.D.OR.255 Changes to the information security management system
GM1 IS.D.OR.255 Changes to the information security management system
GM2 IS.D.OR.255 Changes to the information security management system
IS.D.OR.260 Continuous improvement
The organisation shall assess, using adequate performance indicators, the effectiveness and maturity of the ISMS.
AMC1 IS.D.OR.260 Continuous improvement
GM1 IS.D.OR.260 Continuous improvement
AMC1 IS.D.OR.260(a) Continuous improvement
GM1 IS.D.OR.260(a) Continuous improvement
Appendix I Examples of threat scenarios with a potential harmful impact on safety
The following is a non-exhaustive list of examples of information security threat scenarios with a potential harmful impact on safety that may be…
Appendix II Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0
Part-IS main task Activity type Reference Management, Operational Part-IS EU e-CF NIST CSF 2.0 Competence areas &
Appendix III Examples of aviation services and interfaces
AVIATION SERVICES The following is a non-exhaustive and non-complete list of aviation services that can be used as a basis to identify the scope of the…
Appendix IV Part-IS requirements mapping to ISO/IEC 27001:2022 clauses and controls, and considerations on differences
Although Part-IS does not credit ISO/IEC 27001 certification, the practices and methods typically adopted for implementing and maintaining an ISMS under…
Appendix V Proportionality considerations related to safety relevance and aspects of complexity
The following is a non-exhaustive, non-binding, list of activities related to the implementation of the ISMS under this Regulation.
Appendix VI Adaptation of the EU Cybersecurity Skills Framework (ECSF)
[Figure or form omitted from this preview — available in the Avioverse workspace library.]
Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.
Metis opens with Avioverse in October 2026 · request early access.