Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

Appendix II Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

Delegated Regulation (EU) 2022/1645 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

AppendixAppendix

Appendix IIMain tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

Part-IS main taskActivity typeReference
Management, OperationalPart-ISEU e-CFNIST CSF 2.0
Competence areas & skillsFunctions & categories
Establish and operate an information security management system (ISMS)ManagementIS.D.OR.200(a)ISM (E.08)GV – Govern
Establish the scope of the ISMS in accordance with Part-IS requirementsManagementIS.D.OR.205(a)ISM (E.08)GV.RM – Risk Management Strategy; ID.AM – Asset Management
Implement and maintain an information security policyManagementIS.D.OR.200(a)(1)ISM (E.08)GV.PO – Policy
Identify and review information security risksManagementIS.D.OR.200(a)(2) IS.D.OR.205ISM (E.08), Risk Management (E.02)GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment; ID.IM – Improvement
Implement information security risk treatment measuresManagementIS.D.OR.200(a)(3) IS.D.OR.210ISM (E.08), Risk Management (E.02)ID.RA – Risk Assessment
Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidentsManagementIS.D.OR.200(a)(5) IS.D.OR.220Incident Management (C.04)DE – Detect; RE – Respond; RC – Recover; PR – Protect (as per Risk Assessment)
Implement measures that have been notified by the competent authorityOperationalIS.D.OR.200(a)(6)
Take appropriate remedial actions to address findings notified by the competent authority (non-compliances)BothIS.D.OR.200(a)(7) IS.D.OR.225
Implement an external information security reporting schemeManagementIS.D.OR.200(a)(8) IS.D.OR.230Incident Management (C.04)RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communication
Monitor compliance with this Regulation and report findings to top managementOperationalIS.D.OR.200(a)(12)Compliance (E.09)GV.RR – Roles, Responsibilities and Authorities; GV.RM – Risk Management; GV.OV – Oversight
Protect confidentiality of exchanged informationOperationalIS.D.OR.200(a)(13)Information Security Management (E.08)PR.DS – Data Security; Other PR – Protect categories as applicable
Implement and maintain a continuous improvement process to measure the effectiveness and maturity of the ISMS and strive to improve itManagementIS.D.OR.200(b) IS.D.OR.260Information Security Management (E.08)GV.OV – Oversight; ID.IM – Improvement
Document and maintain all key processes, procedures, roles and responsibilitiesManagementIS.D.OR.200(c)ISM (E.08), Compliance (E.09)GV.RR – Roles, Responsibilities and Authorities; Other functions and categories as applicable
Identify all elements which could be exposed to information security risksManagementIS.D.OR.205(a)Risk Management (E.02)ID.AM – Asset Management
Identify the interfaces with other organisations which could result in exposure to information security risksManagementIS.D.OR.205(b)Risk Management (E.02), Business Change Management (E.07)ID.AM – Asset Management; GV.SC – Cybersecurity Supply Chain Risk Management
Identify information security risks and assign a risk levelManagementIS.D.OR.205(c)Risk Management (E.02)GV.RM – Risk Management Strategy; ID.RA – Risk Assessment
Review and update the risk assessment based on certain criteriaOperationalIS.D.OR.205(d)Risk Management (E.02)GV.RM – Risk Management Strategy; GV.PO – Policy; GV.OV – Oversight; GV.SC – Cybersecurity Supply Chain Risk Management; ID.IM – Improvement
Develop and implement measures to address risks and verify their effectivenessOperationalIS.D.OR.210(a)Risk Management (E.02)GV.RM – Risk Management Strategy; ID.RA – Risk Assessment
Communicate the outcome of the risk assessment to management, other personnel and other organisations sharing an interfaceOperationalIS.D.OR.210(b)Risk Management (E.02), ISM (E.08)GV.RM – Risk Management Strategy; GV.SC – Cybersecurity Supply Chain Risk Management
Establish an internal information security reporting scheme to enable the collection and evaluation of information security events from personnelManagementIS.D.OR.200(a)(4) IS.D.OR.215(a) IS.D.OR.215(e)Incident Management (C.04)ID.RA – Risk Assessment; DE.AE – Adverse Event Analysis; RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communications
Ensure that contracted organisations report information security eventsManagementIS.D.OR.215(c)Supplier Relationship Management (E.10)GV.SC – Cybersecurity Supply Chain Risk Management; DE.CM – Continuous Monitoring
Analyse internally reported occurrences to identify information security events, incidents, and vulnerabilitiesOperationalIS.D.OR.215(b)(1)–(b)(3)Incident Management (C.04)DE.AE – Adverse Event Analysis
Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safetyOperationalIS.D.OR.220(a)ISM (E.08)DE.CM – Continuous Monitoring; DE.AE – Adverse Event Analysis; ID.RA – Risk Assessment; PR – Protect (selection of relevant controls as per Risk Assessment)
Implement measures to respond to information security events that may cause an information security incidentOperationalIS.D.OR.220(b)Incident Management (C.04)RS.MA – Incident Management; RS.AN – Incident Analysis; RS.MI – Incident Mitigation; RS.CO – Incident Response Reporting and Communication (where applicable); PR – Protect (selection of relevant controls as per Risk Assessment)
Cooperate on investigations with other organisations that contribute to the information security of its own activitiesManagementIS.D.OR.215(d)Incident Management (C.04), Legal Advice and Compliance (E.09)DE.CM – Continuous Monitoring; RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communication
Implement measures to recover from information security incidentsOperationalIS.D.OR.220(c)Incident Management (C.04)RC.RP – Incident Recovery Plan Execution; RC.CO – Incident Recovery Communication; PR – Protect (selection of relevant controls as per Risk Assessment)
Manage risks associated with contracted activities with regard to the management of information securityManagementIS.D.OR.235Supplier Relationship Management (E.10)GV.SC – Cybersecurity Supply Chain Risk Management
Create and maintain a process to ensure that there is sufficient personnel to perform all activities regarding information security managementManagementIS.D.OR.240(f)Personnel Development (D.11)GV.RR – Roles, Responsibilities, and Authorities
Create and maintain a process to ensure that the personnel have the necessary competence for activities regarding information security managementManagementIS.D.OR.240(g)Personnel Development (D.11)GV.RR – Roles, Responsibilities, and Authorities; PR.AT – Awareness and Training (02)
Create and maintain a process to ensure that the personnel acknowledge the responsibilities associated with the assigned roles and tasksManagementIS.D.OR.240(h)Personnel Development (D.11)GV.RR – Roles, Responsibilities, and Authorities
Verify the identity and trustworthiness of personnel who have access to information systemsManagementIS.D.OR.240(i)ISM (E.08)GV.RR – Roles, Responsibilities, and Authorities; GV.PO – Policy; PR.AA – entity Management, Authentication, and Access Control
Archive, protect and retain records and ensure they are traceable for a specified timeOperationalIS.D.OR.245ISM (E.08), Compliance (E.09)GV.OV – Oversight; GV.RR – Roles, Responsibilities, and Authorities; PR.DS – Data Security; PR.PS – Platform Security; RS.AN – Incident Analysis; GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment
Correct non-compliance findings upon notification by the competent authority within the period agreed with the competent authorityOperationalIS.D.OR.225
Implement an information security reporting system in accordance with Regulation (EU) No 376/2014ManagementIS.D.OR.230(a)
Report information security incidents or vulnerabilities to the competent authority and, under certain conditions, to othersOperationalIS.D.OR.230(b) IS.D.OR.230(c)Incident Management (C.04)GV.OC – Organisational Context; RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communications
Regularly assess the effectiveness and maturity of the ISMSOperationalIS.D.OR.260(a)ISM (E.08)GV.OV – Oversight; ID.IM – Improvement
Take actions to improve the ISMS if required. Reassess the ISMS elements affected by the implemented measures.OperationalIS.D.OR.260(b)ISM (E.08)GV.OV – Oversight; ID.IM – Improvement
Ensure accessibility of the competent authority to the contracted organisationManagementIS.D.OR.235(b)ISM (E.08)GV.OC – Organisational Context
Top management ensures that all necessary resources are available to comply with the RegulationManagementIS.D.OR.240(a)(1)ISM (E.08)GV.RR – Roles, Responsibilities, and Authorities
Top management establishes and promotes the information security policy and demonstrates a basic understanding of the RegulationManagementIS.D.OR.240(a)(2) IS.D.OR.240(a)(3)ISM (E.08)GV.PO – Policy; GV.PO RR – Roles, Responsibilities, and Authorities
Appoint a responsible person or a group of persons with appropriate knowledge to manage compliance with the RegulationManagementIS.D.OR.240(b) IS.D.OR.240(c) IS.D.OR.240(d)ISM (E.08), Compliance (E.09)GV.PO RR – Roles, Responsibilities, and Authorities
Create and maintain an information security management manual (ISMM)ManagementIS.D.OR.250
Develop a procedure on how to notify the competent authority upon changes to the ISMSManagementIS.D.OR.255(a)Compliance (E.09)GV.OC – Organisational Context; ID.RA – Risk Assessment; ID.IM – Improvement
Manage changes to the ISMS and notify the competent authority and/or request for approval of changesManagementIS.D.OR.255(a) IS.D.OR.255(b)ISM (E.08), Process Improvements (E.05)GV.OC – Organisational Context; ID.RA – Risk Assessment; ID.IM – Improvement

APPENDIX · Appendix II — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.D.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about Appendix II →

Metis opens with Avioverse in October 2026 · request early access.