AppendixAppendix
Appendix IIMain tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0
| Part-IS main task | Activity type | Reference | ||
|---|---|---|---|---|
| Management, Operational | Part-IS | EU e-CF | NIST CSF 2.0 | |
| Competence areas & skills | Functions & categories | |||
| Establish and operate an information security management system (ISMS) | Management | IS.D.OR.200(a) | ISM (E.08) | GV – Govern |
| Establish the scope of the ISMS in accordance with Part-IS requirements | Management | IS.D.OR.205(a) | ISM (E.08) | GV.RM – Risk Management Strategy; ID.AM – Asset Management |
| Implement and maintain an information security policy | Management | IS.D.OR.200(a)(1) | ISM (E.08) | GV.PO – Policy |
| Identify and review information security risks | Management | IS.D.OR.200(a)(2) IS.D.OR.205 | ISM (E.08), Risk Management (E.02) | GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment; ID.IM – Improvement |
| Implement information security risk treatment measures | Management | IS.D.OR.200(a)(3) IS.D.OR.210 | ISM (E.08), Risk Management (E.02) | ID.RA – Risk Assessment |
| Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidents | Management | IS.D.OR.200(a)(5) IS.D.OR.220 | Incident Management (C.04) | DE – Detect; RE – Respond; RC – Recover; PR – Protect (as per Risk Assessment) |
| Implement measures that have been notified by the competent authority | Operational | IS.D.OR.200(a)(6) | ||
| Take appropriate remedial actions to address findings notified by the competent authority (non-compliances) | Both | IS.D.OR.200(a)(7) IS.D.OR.225 | ||
| Implement an external information security reporting scheme | Management | IS.D.OR.200(a)(8) IS.D.OR.230 | Incident Management (C.04) | RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communication |
| Monitor compliance with this Regulation and report findings to top management | Operational | IS.D.OR.200(a)(12) | Compliance (E.09) | GV.RR – Roles, Responsibilities and Authorities; GV.RM – Risk Management; GV.OV – Oversight |
| Protect confidentiality of exchanged information | Operational | IS.D.OR.200(a)(13) | Information Security Management (E.08) | PR.DS – Data Security; Other PR – Protect categories as applicable |
| Implement and maintain a continuous improvement process to measure the effectiveness and maturity of the ISMS and strive to improve it | Management | IS.D.OR.200(b) IS.D.OR.260 | Information Security Management (E.08) | GV.OV – Oversight; ID.IM – Improvement |
| Document and maintain all key processes, procedures, roles and responsibilities | Management | IS.D.OR.200(c) | ISM (E.08), Compliance (E.09) | GV.RR – Roles, Responsibilities and Authorities; Other functions and categories as applicable |
| Identify all elements which could be exposed to information security risks | Management | IS.D.OR.205(a) | Risk Management (E.02) | ID.AM – Asset Management |
| Identify the interfaces with other organisations which could result in exposure to information security risks | Management | IS.D.OR.205(b) | Risk Management (E.02), Business Change Management (E.07) | ID.AM – Asset Management; GV.SC – Cybersecurity Supply Chain Risk Management |
| Identify information security risks and assign a risk level | Management | IS.D.OR.205(c) | Risk Management (E.02) | GV.RM – Risk Management Strategy; ID.RA – Risk Assessment |
| Review and update the risk assessment based on certain criteria | Operational | IS.D.OR.205(d) | Risk Management (E.02) | GV.RM – Risk Management Strategy; GV.PO – Policy; GV.OV – Oversight; GV.SC – Cybersecurity Supply Chain Risk Management; ID.IM – Improvement |
| Develop and implement measures to address risks and verify their effectiveness | Operational | IS.D.OR.210(a) | Risk Management (E.02) | GV.RM – Risk Management Strategy; ID.RA – Risk Assessment |
| Communicate the outcome of the risk assessment to management, other personnel and other organisations sharing an interface | Operational | IS.D.OR.210(b) | Risk Management (E.02), ISM (E.08) | GV.RM – Risk Management Strategy; GV.SC – Cybersecurity Supply Chain Risk Management |
| Establish an internal information security reporting scheme to enable the collection and evaluation of information security events from personnel | Management | IS.D.OR.200(a)(4) IS.D.OR.215(a) IS.D.OR.215(e) | Incident Management (C.04) | ID.RA – Risk Assessment; DE.AE – Adverse Event Analysis; RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communications |
| Ensure that contracted organisations report information security events | Management | IS.D.OR.215(c) | Supplier Relationship Management (E.10) | GV.SC – Cybersecurity Supply Chain Risk Management; DE.CM – Continuous Monitoring |
| Analyse internally reported occurrences to identify information security events, incidents, and vulnerabilities | Operational | IS.D.OR.215(b)(1)–(b)(3) | Incident Management (C.04) | DE.AE – Adverse Event Analysis |
| Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safety | Operational | IS.D.OR.220(a) | ISM (E.08) | DE.CM – Continuous Monitoring; DE.AE – Adverse Event Analysis; ID.RA – Risk Assessment; PR – Protect (selection of relevant controls as per Risk Assessment) |
| Implement measures to respond to information security events that may cause an information security incident | Operational | IS.D.OR.220(b) | Incident Management (C.04) | RS.MA – Incident Management; RS.AN – Incident Analysis; RS.MI – Incident Mitigation; RS.CO – Incident Response Reporting and Communication (where applicable); PR – Protect (selection of relevant controls as per Risk Assessment) |
| Cooperate on investigations with other organisations that contribute to the information security of its own activities | Management | IS.D.OR.215(d) | Incident Management (C.04), Legal Advice and Compliance (E.09) | DE.CM – Continuous Monitoring; RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communication |
| Implement measures to recover from information security incidents | Operational | IS.D.OR.220(c) | Incident Management (C.04) | RC.RP – Incident Recovery Plan Execution; RC.CO – Incident Recovery Communication; PR – Protect (selection of relevant controls as per Risk Assessment) |
| Manage risks associated with contracted activities with regard to the management of information security | Management | IS.D.OR.235 | Supplier Relationship Management (E.10) | GV.SC – Cybersecurity Supply Chain Risk Management |
| Create and maintain a process to ensure that there is sufficient personnel to perform all activities regarding information security management | Management | IS.D.OR.240(f) | Personnel Development (D.11) | GV.RR – Roles, Responsibilities, and Authorities |
| Create and maintain a process to ensure that the personnel have the necessary competence for activities regarding information security management | Management | IS.D.OR.240(g) | Personnel Development (D.11) | GV.RR – Roles, Responsibilities, and Authorities; PR.AT – Awareness and Training (02) |
| Create and maintain a process to ensure that the personnel acknowledge the responsibilities associated with the assigned roles and tasks | Management | IS.D.OR.240(h) | Personnel Development (D.11) | GV.RR – Roles, Responsibilities, and Authorities |
| Verify the identity and trustworthiness of personnel who have access to information systems | Management | IS.D.OR.240(i) | ISM (E.08) | GV.RR – Roles, Responsibilities, and Authorities; GV.PO – Policy; PR.AA – entity Management, Authentication, and Access Control |
| Archive, protect and retain records and ensure they are traceable for a specified time | Operational | IS.D.OR.245 | ISM (E.08), Compliance (E.09) | GV.OV – Oversight; GV.RR – Roles, Responsibilities, and Authorities; PR.DS – Data Security; PR.PS – Platform Security; RS.AN – Incident Analysis; GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment |
| Correct non-compliance findings upon notification by the competent authority within the period agreed with the competent authority | Operational | IS.D.OR.225 | ||
| Implement an information security reporting system in accordance with Regulation (EU) No 376/2014 | Management | IS.D.OR.230(a) | ||
| Report information security incidents or vulnerabilities to the competent authority and, under certain conditions, to others | Operational | IS.D.OR.230(b) IS.D.OR.230(c) | Incident Management (C.04) | GV.OC – Organisational Context; RS.CO – Incident Response Reporting and Communication; RC.CO – Incident Recovery Communications |
| Regularly assess the effectiveness and maturity of the ISMS | Operational | IS.D.OR.260(a) | ISM (E.08) | GV.OV – Oversight; ID.IM – Improvement |
| Take actions to improve the ISMS if required. Reassess the ISMS elements affected by the implemented measures. | Operational | IS.D.OR.260(b) | ISM (E.08) | GV.OV – Oversight; ID.IM – Improvement |
| Ensure accessibility of the competent authority to the contracted organisation | Management | IS.D.OR.235(b) | ISM (E.08) | GV.OC – Organisational Context |
| Top management ensures that all necessary resources are available to comply with the Regulation | Management | IS.D.OR.240(a)(1) | ISM (E.08) | GV.RR – Roles, Responsibilities, and Authorities |
| Top management establishes and promotes the information security policy and demonstrates a basic understanding of the Regulation | Management | IS.D.OR.240(a)(2) IS.D.OR.240(a)(3) | ISM (E.08) | GV.PO – Policy; GV.PO RR – Roles, Responsibilities, and Authorities |
| Appoint a responsible person or a group of persons with appropriate knowledge to manage compliance with the Regulation | Management | IS.D.OR.240(b) IS.D.OR.240(c) IS.D.OR.240(d) | ISM (E.08), Compliance (E.09) | GV.PO RR – Roles, Responsibilities, and Authorities |
| Create and maintain an information security management manual (ISMM) | Management | IS.D.OR.250 | ||
| Develop a procedure on how to notify the competent authority upon changes to the ISMS | Management | IS.D.OR.255(a) | Compliance (E.09) | GV.OC – Organisational Context; ID.RA – Risk Assessment; ID.IM – Improvement |
| Manage changes to the ISMS and notify the competent authority and/or request for approval of changes | Management | IS.D.OR.255(a) IS.D.OR.255(b) | ISM (E.08), Process Improvements (E.05) | GV.OC – Organisational Context; ID.RA – Risk Assessment; ID.IM – Improvement |
APPENDIX · Appendix II — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025