Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.D.OR.200 Information security management system (ISMS)

Delegated Regulation (EU) 2022/1645 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.D.OR.200Information security management system (ISMS)

(a)In order to achieve the objectives set out in Article 1, the organisation shall set up, implement and maintain an information security management system (ISMS) which ensures that the organisation:

(1)establishes a policy on information security setting out the overall principles of the organisation with regard to the potential impact of information security risks on aviation safety;

(2)identifies and reviews information security risks in accordance with point IS.D.OR.205;

(3)defines and implements information security risk treatment measures in accordance with point IS.D.OR.210;

(4)implements an information security internal reporting scheme in accordance with point IS.D.OR.215;

(5)defines and implements, in accordance with point IS.D.OR.220, the measures required to detect information security events, identifies those events which are considered incidents with a potential impact on aviation safety, and responds to, and recovers from, those information security incidents;

(6)implements the measures that have been notified by the competent authority as an immediate reaction to an information security incident or vulnerability with an impact on aviation safety;

(7)takes appropriate action, in accordance with point IS.D.OR.225, to address findings notified by the competent authority;

(8)implements an external reporting scheme in accordance with point IS.D.OR.230 in order to enable the competent authority to take appropriate actions;

(9)complies with the requirements contained in point IS.D.OR.235 when contracting any part of the activities referred to in point IS.D.OR.200 to other organisations;

(10)complies with the personnel requirements laid down in point IS.D.OR.240;

(11)complies with the record-keeping requirements laid down in point IS.D.OR.245;

(12)monitors compliance of the organisation with the requirements of this Regulation and provides feedback on findings to the accountable manager or, in the case of design organisations, to the head of the design organisation, in order to ensure effective implementation of corrective actions;

(13)protects, without prejudice to applicable incident reporting requirements, the confidentiality of any information that the organisation may have received from other organisations, according to its level of sensitivity.

(b)In order to continuously meet the requirements referred to in Article 1, the organisation shall implement a continuous improvement process in accordance with point IS.D.OR.260.

(c)The organisation shall document, in accordance with point IS.D.OR.250, all key processes, procedures, roles and responsibilities required to comply with point IS.D.OR.200(a) and establish a process for amending that documentation. Changes to those processes, procedures, roles and responsibilities shall be managed in accordance with point IS.D.OR.255.

(d)The processes, procedures, roles and responsibilities established by the organisation in order to comply with point IS.D.OR.200(a) shall correspond to the nature and complexity of its activities, based on an assessment of the information security risks inherent to those activities, and may be integrated within other existing management systems already implemented by the organisation.

(e)Without prejudice to the obligation to comply with the reporting requirements contained in Regulation (EU) No 376/2014 and the requirements of point IS.D.OR.200(a)(13), the organisation may be granted approval by the competent authority not to implement the requirements referred to in points (a) to (d) ) and the related requirements contained in points IS.D.OR.205 through IS.D.OR.260, if it demonstrates to the satisfaction of that authority that its activities, facilities and resources, as well as the services it operates, provides, receives and maintains, do not pose any information security risks with a potential impact on aviation safety neither to itself nor to other organisations. The approval shall be based on a documented information security risk assessment carried out by the organisation or a third party in accordance with point IS.D.OR.205 and reviewed and approved by its competent authority. The continued validity of that approval will be reviewed by the competent authority following the applicable oversight audit cycle and whenever changes are implemented in the scope of work of the organisation.

IR · IS.D.OR.200 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2025/22 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.200Information security management system (ISMS)

Show the text

An information security management system (ISMS) is a systematic approach to establish, implement, operate, monitor, review, maintain and continuously improve the state of information security of an organisation. Its objective is to protect the information assets, such that the operational and safety objectives of an organisation can be reached in a risk-aware, effective and efficient manner. Generally speaking, an ISMS establishes an information security risk management process, based upon the results of information security impact analyses, which basically determine its scope. If information security breaches may cause or contribute to aviation safety consequences, information security requirements need to limit the impact or influence of information security breaches on levels of aviation safety, which are deemed acceptable. Hence, all roles, processes, or information systems, which may cause or contribute to aviation safety consequences, are within the scope of Regulation (EU) 2022/1645. The ISMS provides for means to decide on needed information security controls for all architectural layers (governance, business, application, technology, data) and domains (organisational, human, physical, technical). It further allows to manage the selection, implementation, and operation of information security controls. Finally, it allows to manage the governance, risk management and compliance (GRC) within the ISMS scope. The overall risk assessment considers safety consequences influenced by information security risks. These may emerge as threats, hazards, escalation factors that weaken barriers, or direct triggers of existing hazards. When conducting this assessment, both aspects, information security and safety need to be coordinated throughout the process. This ensures mutual understanding of the objectives and the implementation of preventive measures against all types of threats or weaknesses, as well as mitigating measures. The risk management process is thus based on aviation safety risk assessments and derived information security risk acceptance levels, which are designed to effectively treat and manage information security risks with a potential impact on aviation safety caused by threats exploiting vulnerabilities of information assets in aeronautical systems. Interacting bow-ties is one possible way that allows for a higher level and non-exhaustive illustration of how different disciplines of risk assessment may need to collaborate to establish a common risk perspective. The below Figure 1 from ICAO Doc 10204 ‘Manual on Aviation Information Security’ illustrates these interactions. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 1: Bow-tie representation of management of aviation safety risks posed by information security threats

In the drawing, the term ‘context’ in the communication between the safety assessment process (SAP) and the information security assessment process (ISAP) carries slightly different notions, which need to be understood and distinguished. In order to satisfy the safety requirements, the SAP will provide context information such as: the architecture of the systems and the functional descriptions of the elements within the scope, including those related to the barriers. Systems should be understood as the dynamic interaction between people, processes, and products or services; all identified relevant safety hazards; the top events and their relations (e.g. triggers) to those hazards. In addition to context information, it provides the target likelihood of the related information security successful compromise. This target likelihood is commensurate with the safety objectives related to the severity of the safety consequence. However, it needs to be complemented to include information about the acceptable level of uncertainty, in order to be able to rely adequately on the results of the ISAP. In turn, the ISAP will return context information such as: modification to the architecture of the systems and functional descriptions of the elements modified or added, whether those were safety barriers or other items; additional threats; potentially additional safety hazards; additional direct triggers of hazards; additional escalating factors affecting barriers. In addition to context information, it provides the achieved likelihood of an information security successful compromise. While this likelihood is consistent with the safety objectives set by the SAP, the achieved level of uncertainty also needs to be considered. The interaction between SAP and ISAP is iterative and continues until the safety risk is acceptable, i.e. the target likelihood of the related information security successful compromise has been achieved. The interaction can start from safety consequences identified through the SAP that fall within the scope of the ISMS risk analysis, or from existing information security assessments. ISMS implementation and maintenance An ISMS, as defined in this Regulation, employs the perspectives of governance, risk and compliance, and an approach that combines the safety risk and performance dimensions to determine the information security controls that are appropriate and compliant with the specific context and can effectively provide the level of protection required to achieve the aviation safety objectives by: Governance perspective refers to providing management direction and leadership aimed to achieve the entity’s own overarching objectives: leadership and commitment of the senior management defining and ensuring the close involvement of the management and a ‘top-down’ ISMS implementation information security and safety objectives aligned and consistent with the entity’s business objectives and monitored by, e.g., management reviews information security policies stating the principles and objectives to be achieved roles, responsibilities, competencies and resources required for an effective ISMS effective, target-group-oriented communication to internal and external stakeholders Risk perspective refers to a key aspect of an ISMS in an aviation safety context according to this Regulation and serves as a basis for transparent decision-making and prioritisation of controls and risk treatment options. It further refers to the assessment, treatment and monitoring of information security risks in support of the management of aviation safety risks for the key processes and information assets upon which they depend. This includes protection requirements, risk exposure, attitude towards risks and risk acceptance criteria, methods and industry standards. Compliance perspective refers to the compliance with regulatory, legal and contractual requirements. This includes: this Regulation, the entity’s own policies and standards and may further include international or industry standards adopted by the entity from ISO, EUROCAE, etc. This perspective comprises the definition, implementation and maintenance of the required information security provisions whose effectiveness and compliance should be regularly monitored and assured by, e.g. (internal) audits. Based on these perspectives we may identify the following processes or subject areas that have been shown to be relevant for the establishment of an effective ISMS. These ISMS processes and subject areas can be summarised as follows:

(a)context establishment defining the scope, interfaces, dependencies and requirements of interested parties;

(b)leadership and commitment of the senior management;

(c)information security and safety objectives;

(d)information security policies;

(e)roles, responsibilities, competencies and resources required for an effective ISMS;

(f)communication to internal and external stakeholders to achieve a sufficient level of information security awareness and training of all involved parties;

(g)information security risk management including risk assessment and treatment;

(h)information security incident management establishing processes for the handling of information security incidents and vulnerabilities;

(i)performance & effectiveness monitoring, measurement and evaluation;

(j)internal audits and management reviews;

(k)corrections and corrective actions;

(l)continuous improvement;

(m)relationship with suppliers;

(n)documentation, record-keeping, and evidence collection. Additional critical success factors for the implementation and operation of an ISMS include the following: The ISMS should be integrated with the entity’s processes and overall management structure or even — at least partially, with safeguards for their respective integrity, and as reasonably applicable — with an overarching management system comprising information security, aviation safety and quality management. Information security has to be considered at an early stage in the overall design of processes and procedures, of systems and of information security controls, to be seamlessly integrated, for maximum effectiveness, minimal functional interference and optimised cost. None of these benefits can be achieved by integrating it on later. The risk management process determines appropriate characteristics of preventive controls to reach and maintain acceptable risk levels. The incident management process ensures that the organisation detects, reacts and responds to information security incidents in a timely manner. This is achieved by defining responsibilities, procedures, scenarios and response plans in advance to ensure a coordinated, targeted and efficient response. Continuous monitoring and reassessment are undertaken and improvements are made in response. The above-mentioned core components are related to the requirements in this Regulation, for which Figure 2 provides a high-level depiction of the aspects that are more prominent in the implementation phase and those that characterise the operational phase, as well as the review and possible improvement, if the functions do not perform as planned [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 2: Representation of the Part-IS requirements from an ISMS’s life cycle perspective

Plan-Do-Check-Act approach The Plan-Do-Check-Act (PDCA) refers to a process approach that is often used to establish, implement, operate, monitor, review and improve management systems. Figure 3 depicts the PDCA applied to an ISMS. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 3: Plan-Do-Check-Act approach applied to an ISMS

Benefits of an ISMS The benefits of a management system operating in a dynamic, uncertain or unpredictable risk environment are realised in the long term only when the organisation improves existing controls, processes and solutions based on the assessments of risks, performance and maturity as well as on the learnings from incidents, audits, non-conformities and their root causes. A successful adoption and deployment of an ISMS allows an entity to: achieve greater assurance to the management and interested parties that its information assets are adequately protected against threats on a continual basis; increase its trustworthiness and credibility providing confidence to interested parties that information security risks with an impact on aviation safety are adequately managed; increase the resilience of the entity’s key processes against unauthorised electronic interactions and maintains the entity’s ability to decide and act; support the timely detection of control gaps, vulnerabilities or deficiencies aimed to prevent information security incidents or at least to minimise their impact; detect and timely react to changes in the entity’s environment including system architecture and threat landscape or the adoption of new technologies; provide a foundation for effective and efficient implementation of a comprehensive information security strategy in times of digital transformation, increasing interconnectivity of systems, emerging information security threats and new technologies. Relation to ISO/IEC 27001 The international standard ISO/IEC 27001 is a widely adopted standard for ISMS which specifies generic requirements for establishing, implementing, maintaining and continually improving an ISMS. It also includes requirements for the assessment and treatment of information security risks. The requirements are applicable to all entities, regardless of type, size or nature. The conformity of an ISMS with the ISO/IEC 27001 standard can be certified by an accredited certification body. ISO/IEC 27001 is compatible with other management system standards (quality, safety, etc.) that have also adopted the structure and terms defined in Annex SL to ISO/IEC Directives, Part 1, Consolidated ISO Supplement. This compatibility allows an entity to operate a single management system that meets the requirements of multiple management system standards. ISO/IEC 27001 allows entities to define their own scope of audit and their own organisational risk appetite. This, in turn, leads to information security requirements that provide the ISMS with criteria for the acceptability of information security risks in line with the entity’srisk appetite (see Figure4). [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 4: Relation between the entity’s risk appetite and the information security objectives

The requirements for an ISMS specified by this Regulation are in most parts consistent and aligned with ISO/IEC 27001; however, this Regulation introduces provisions specific to the context of aviation safety. If an ISO/IEC 27001-based ISMS is already operated by an entity for a different scope and context, it can be adapted and extended to the scope and context of this Regulation in a straightforward manner based on an analysis of the scope and the gaps. In order to take credit from ISO/IEC 27001 certifications to achieve compliance with Part-IS, aviation safety needs to be included in the organisational risk management, with the relevant risk acceptance level determined by the applicable regulation (see Figure 5). Therefore, careful determination of the scope of the ISMS related to aviation safety risks is needed, as it might differ from the one related to the other organisational risks. To allow demonstration of compliance with Regulation (EU) 2022/1645, careful delineation between aspects of the ISMS related to aviation safety risks and other organisational risks may be required. This could have an influence upon the decision to integrate ISMSs. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 5: Introduction of aviation safety aspects in the entity’s risk appetite

PART-IS versus ISO/IEC 27001 cross reference table For a mapping between the Part-IS provisions and the clauses and associated controls in ISO/IEC 27001:2022, refer to Appendix IV.

GM · GM1 IS.D.OR.200 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.200(a)(1)Information security management system (ISMS)

Show the text

The organisation should define and document the scope of the ISMS, by determining activities, processes, supporting systems, and identifying those which may have an impact on aviation safety. The information security policy should be endorsed by the accountable manager or, in the case of design organisations, by the head of the design organisation, and reviewed at planned intervals or if significant changes occur. Moreover, the policy should cover at least the following aspects with a potential impact on aviation safety by:

(a)committing to comply with applicable legislation, consider relevant standards and best practices;

(b)setting objectives and performance measures for managing information security;

(c)defining general principles, activities, processes for the organisation to appropriately secure information and communication technology systems and data;

(d)committing to apply ISMS requirements into the processes of the organisation;

(e)committing to continually improve towards higher levels of information security process maturity as per IS.D.OR.260;

(f)committing to satisfy applicable requirements regarding information security and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation;

(g)assigning information security as one of the essential responsibilities for all managers;

(h)committing to promote the information security policy through training or awareness sessions within the organisation to all personnel on a regular basis or upon modifications;

(i)encouraging the implementation of a ‘Just-(Culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents;

(j)committing to communicate the information security policy to all relevant parties, as appropriate. Note: A significant change is a notable alteration or modification that has a meaningful impact on the organisation’s operations, such as a structural change within the organisation due to reorganisations, a change in the business processes (e.g. working from home, use of personal devices), a technological evolution (e.g. distributed computing resources, artificial intelligence/machine learning) or an evolution in the threat landscape.

AMC · AMC1 IS.D.OR.200(a)(1) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.200(a)(1)Information security management system (ISMS)

Show the text

INFORMATION SECURITY POLICY AND OBJECTIVES The information security policy should suit to the organisation’s purpose and direct its own information security activities. Such policy should contain the needs for information security in the organisation’s context, a high-level statement of direction and intent of the information security activities, the principles and most important strategic and tactical objectives to be achieved by the ISMS, as well as the general information security objectives or a specification of a framework (who, how) for setting information security objectives. The information security policy should also contain a description of the established ISMS including roles, responsibilities and references to topic-specific policies and standards. The information security objectives should be: consistent and aligned with the information security policy and consider the applicable information security requirements, derived from the overarching organisation’s objectives, and the results from the risk assessment and treatment (which, in turn, supports the implementation of the organisation’s strategic goals and information security policy); regularly reviewed to ensure that they are up to date and still appropriate; measurable if practicable (to be able to determine whether the objective has been met), aimed to be SMART (specific, measurable, attainable, realistic, timely) and aligned with all affected responsible persons. When defining information security objectives, e.g., based on the overarching organisation’s objectives, the information security requirements or the results of risk assessments, it should be determined how these objectives will be achieved. The degree to which IS objectives are achieved must be measurable. If possible, it should be measured by key performance indicators (KPIs) which have been defined in advance (refer to resources such as COBIT 5 for Information Security). It is recommended to start with the definition of a limited number of information security objectives which are relevant for the entity, more of a long-term nature and measurable with a reasonable effort relative to the delivered benefits.

GM · GM1 IS.D.OR.200(a)(1) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.200(a)(12)Information security management system (ISMS)

Show the text

COMPLIANCE MONITORING When establishing compliance with the provisions under points IS.D.OR.200(a)(12) the organisation should implement a function to periodically monitor compliance of the management system with the relevant requirements and adequacy of the procedures including the establishment of an internal audit process and an information security risk management process. When the organisation has already established a compliance monitoring function under the implementing regulation for its domain, such function should include the monitoring of the management system with the relevant requirements within the scope of its activities. Compliance monitoring should include a feedback mechanism of audit findings to the accountable manager or, in the case of design organisations, to the head of the design organisation, or delegated persons to ensure implementation of corrective actions as necessary.

AMC · AMC1 IS.D.OR.200(a)(12) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.200(a)(12)Information security management system (ISMS)

Show the text

COMPLIANCE MONITORING For the purpose of compliance monitoring, internal audits should be conducted at planned intervals to provide assurance on the status of the ISMS to the management and to provide information on the following: conformity of the ISMS to the requirements of this Regulation and the organisation’s own requirements either stated in the information security policy, procedures and contracts or derived from information security objectives or outcomes of the risk treatment process; effective implementation and maintenance of the ISMS. Internal audits should follow an independent approach and a decision-making process based on evidences. Moreover, when setting up an audit programme the importance of the processes concerned, and definitions of the audit criteria and scopes should be considered. Documented information should be retained evidencing the audit results, their reporting to the relevant management and the audit programme.

GM · GM1 IS.D.OR.200(a)(12) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.200(a)(13)Information security management system (ISMS)

Show the text

When establishing compliance with the provisions under points IS.D.OR.200(a)(13), the organisation should implement and maintain information security controls that are sufficiently robust and effective to protect information and ensure the need-to-know principle (i.e. limiting access to information to only those who need it to perform their duties). It should protect the source of information in accordance with the relevant provisions established in Regulation (EU) 2018/1139. It should also comply with Regulation (EU) No 376/2014.

AMC · AMC1 IS.D.OR.200(a)(13) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.200(c)Information security management system (ISMS)

Show the text

When establishing compliance with the provisions under point IS.D.OR.200(c), the organisation should:

(a)provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities. This outline of the structure will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the accountable manager or, in the case of design organisations, by the head of the design organisation. The organisation should review the outline of the structure at planned intervals or if significant changes occur (see the Note in AMC1 IS.D.OR.200(a)(1));

(b)identify and categorise all relevant contracted organisations used to implement the ISMS. The organisation should define and document procedures for the management of interfaces and coordination between the organisation and other organisations, including contracted organisations;

(c)identify and define all key processes and procedures, and internal and external reporting schemes that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The organisation may adjust existing processes or procedures for compliance;

(d)identify and document any other information that will be used to maintain compliance with the objectives of this Regulation;

(e)when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy;

(f)control the documented information required by the ISMS to ensure that it is:

(1)available and suitable for use, where and when it is needed;

(2)adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).

AMC · AMC1 IS.D.OR.200(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.200(c)Information security management system (ISMS)

Show the text

The amount of information that should be documented to maintain compliance with the objectives of this Regulation may vary between organisations due to various factors, such as size and complexity, or the need for harmonisation with other management processes already in place. As general guidance, taking into account the documents required to comply with point IS.D.OR.200(a), the record-keeping requirements referred to in IS.D.OR.245 and the information security management manual requirements referred to in IS.D.OR.250, the following is a non-exhaustive list of information that should be documented:

(a)information security policy that should include the organisation’s information security objectives — see IS.D.OR.200(a)(1);

(b)responsibilities and accountabilities for roles relevant to information security — see IS.D.OR.250(a)(2), (3), (6) and (7) and the personnel requirements referred to in points IS.D.OR.240(a), (b), (c), (d) and (f) and the related AMC and GM;

(c)scope of the ISMS and the interfaces with, and dependencies on, other parties — see IS.D.OR.200(a)(2) and the information security requirements referred to in points IS.D.OR.205(a) and (b);

(d)information security risk management process — see the information security requirements referred to in points IS.D.OR.205 and IS.D.OR.210;

(e)archive of the risks identified in the information security risk assessment along with the associated risk treatment measures (often referred to as ‘risk register’ or ‘risk ledger’) — see IS.D.OR.245;

(f)evidence of the competencies necessary for the personnel performing the activities required under this Regulation — see IS.D.OR.240(g) and the related AMC and GM;

(g)evidence of the current competencies of the personnel performing the activities required under this Regulation — see IS.D.OR.245(b)(1);

(h)(key) performance indicators derived from evidence of the monitoring and measurement of the ISMS processes.

GM · GM1 IS.D.OR.200(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.200(d)Information security management system (ISMS)

Show the text

PROPORTIONALITY IN ISMS IMPLEMENTATION When implementing the processes and procedures, as well as establishing the roles and responsibilities required under point IS.D.OR.200(d), the organisation should primarily consider the risks that it may be posing to other organisations, as well as its own risk exposure. Other aspects that may be relevant include the organisation’s needs and objectives, information security requirements, its own processes and the size, complexity and structure of the organisation, all of which may change over time. As a general guide, the following aspects of the degree of safety relevance and organisational complexity could be taken into account when defining the ISMS. Each of these influences the implementation of the ISMS in certain areas:

(a)The organisation’s position in the functional chain and the number and degree of safety relevance of the interfacing organisations/stakeholders.

(b)The complexity of the organisational structure and hierarchies (e.g. number of staff, departments, hierarchical layers, external location, subsidiaries, etc.)

(c)The complexity of the information and communication technology systems and data used by the organisation and their connection to external parties. More details on the influence on the proportionate implementation of Part-IS for each aspect of safety relevance and organisational complexity are provided in Appendix V.

SUPPORTED IMPLEMENTATION OF THE ISMS In the context of Part-IS, all organisations initiate the implementation of an ISMS with determining its scope, which in turn is based upon at least an assessment of aviation safety impacts for which information security incidents are a cause or a contributing factor. Organisations, irrespective of their size, may not have yet sufficient knowledge about their information security risks, and may consider seeking support by a service provider that can also provide additional personnel and expertise during this implementation phase of the ISMS. The same may apply to later phases of the ISMS implementation, and to this end organisations may want to consider the provision of IS.D.OR.235 and related AMC. Outsourcing specific ISMS functions, such as information security monitoring or incident response to service providers, may help ensure that the organisation has access to experienced personnel and expertise. Similarly, organisations may want to be supported by a service provider in performing risk assessments. Regarding the establishment of the appropriate personnel to implement and comply with the provisions of this Regulation, organisations should always refer to AMC1 IS.D.OR.240(f) and GM1 IS.D.OR.240(f), by considering that multiple responsibilities may be assigned to one person, while always ensuring the independence of the compliance monitoring. As an introduction to the nature of information security risks and their management, organisations may use, as initial guidance, the NIST Interagency Report (NISTIR 7621 Rev.1) ‘Small Business Information Security: The Fundamentals’. INTEGRATION OF ISMS UNDER THIS REGULATION WITH EXISTING MANAGEMENT SYSTEMS An organisation may take advantage of existing management systems when implementing an ISMS by integrating it with those existing systems. By integrating the ISMS with existing management systems, the organisation may reduce the effort and costs required to implement and maintain the ISMS, while also ensuring consistency and alignment with the organisation’s overall management approach. Below is a non-exhaustive list of potential synergies that can be exploited when integrating the ISMS with an existing management system: Leverage existing policies and procedures: an organisation may use its existing policies and procedures as a foundation for its ISMS. This may help to ensure consistency and minimise the need for additional documentation. Align ISMS with other management systems: an organisation may align the ISMS with other management systems, such as safety management systems (SMS), to ensure that the ISMS is consistent with the organisation’s overall management approach. Use existing risk management processes: an organisation may use their existing risk management processes to identify and assess the information security risks potentially leading to aviation safety risks. Reuse existing controls: an organisation may reuse existing controls, such as access controls or incident management process, to implement the information security controls required by the ISMS. Continuous improvement process: an organisation may use the continuous improvement process of existing management systems to improve the ISMS over time.

GM · GM1 IS.D.OR.200(d) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.200(e)Information security management system (ISMS)

Show the text

DEROGATION Organisations should follow the directions provided in AMC1 IS.D.OR.205(a) and AMC1 IS.D.OR.205(b) to perform a documented information security risk assessment to seek the approval from the competent authority of a derogation under point IS.D.OR.200(e). In order to justify the grounds for an derogation, the risk assessment is expected to provide explanations for the exclusion of all elements from the scope of the ISMS. It is up to the authority to determine whether this assessment is deemed satisfactory for a derogation to be granted. Organisations that would like to have the risk assessment performed by a third party should consider the requirements of IS.D.OR.235 and the related AMC.

AMC · AMC1 IS.D.OR.200(e) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.200(e)Information security management system (ISMS)

Show the text

Any organisation that believes that it does not pose any information security risk with a potential impact on aviation safety, either to itself or to other organisations, may consider requesting an approval for a derogation by the competent authority following the procedure outlined in AMC1 IS.D.OR.200(e). Existing safety risk assessments, such as those carried out as part of the SMS, can form the basis of enhanced assessments considering safety risks arising from information security threats. It should be noted that applications for partial exemption from individual articles are not possible.

APPLICATION FOR A DEROGATION In order to ensure a consistent approach by organisations when submitting a derogation request, the competent authority may establish an official derogation request application form. The application for a derogation, based on the application form where one exists or in a format decided by the organisation, will need to be signed by the accountable manager of the applicant organisation and submitted to the appropriate competent authority for review and consideration. The application for a derogation should contain preliminary information used for a pre-assessment by the competent authority, including: Company information and contact information; Affected approval(s); Detailed justification for the exclusion of the provisions; Overview of services that the organisation provides and receives; Architecture overview of information systems used for business operation; Summary of the high-level information security risk assessment aligned with the above architecture; Methodology used to perform the information security risk assessment; List of people and roles involved in the information security risk assessment process; Date and signature. Note: At this stage, the high-level risk assessment needs to properly document the absence of information security risks that may impact safety. To do so, it should at least cover the identification of the scope and boundaries, as required under points IS.D.OR.205 (a) and (b), and the analysis of safety impact, as required under point IS.D.OR.205(c).

EVALUATION OF THE REQUEST FOR A DEROGATION The competent authority reviews the information security risk assessment and other supporting documentation, normally assessing whether: the documentation is sufficient for a proper analysis and assessment; the repository or asset inventory of digital systems, data flows and processes is comprehensive; the high-level information security risk assessment has been conducted in accordance with the organisation’s methodology and with the appropriate diligence; the relevant stakeholders have been involved in the assessment process; the assessment has been performed by people with sufficient expertise in information security and aviation safety; the organisation has assigned and indicated a point of contact for enquiries. Figure 1 below depicts the process, including the pre-assessment. If the pre-assessment provides the competent authority with sufficient evidence that the derogation request is legitimate and that the organisation meets the expected criteria, the process will proceed to the exchange of more detailed information. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 1: Representation of the derogation process Note 1 to Figure 1: The objective of this step is to obtain preliminary information about the organisation risk profile by using suitable means (e.g. questionnaire, self-assessment template, request tool, etc.) Note 2 to Figure 1: The objective of this step is to conduct a pre-evaluation to check whether the organisation has the possibility to be granted a derogation. The pre-assessment allows to avoid a detailed assessment if the prerequisites for a derogation are not met.

EXPECTATIONS AND RECOMMENDATION AFTER DEROGATION APPROVAL Once a derogation approval has been granted, the organisation is expected to undertake the following on a continuous basis: Comply with all provisions of the regulation which are not exempted, in particular point IS.D.OR.200(a)(13) which should not be limited to only protection of the received information. When transmitting information with confidential nature, the organisation needs to have secure means in place as well; Comply with Regulation (EU) No 376/2014 to take into account the obligation to comply with the reporting requirements. Monitor any changes in the organisation’s scope of work and identify those which may have a potential impact on the documented information, which supports the derogation approval. Where such changes are identified, the organisation should ensure that they are brought to the attention of the competent authority without delay and notified in accordance with the applicable implementing rule. Monitor the risk picture for any variation due to changes in the safety and security environment over time. To this end, point IS.D.OR.205(d) should be considered. Ensure that the accountable manager or the head of the design of the organisation can demonstrate an understanding of the derogation process and the terms on which the approval has been granted. This means that at least one person in the organisation needs to have a basic understanding of the Regulation. To this end, point IS.D.OR.240(a)(3) and the related AMC and GM should be considered. Implement basic protection against information security risks according to industry best practices. Remain up to date with the latest information security threat landscape and consult the respective national authority for additional guidance.

EXAMPLES An example of organisations that may consider asking for a derogation might include DOA or POA holders that design or produce only components or parts that either are not involved in ensuring the structural integrity of the aircraft (e.g. carpets, interiors) or have no major safety-related aircraft functionalities, including but not limited to, aircraft software, navigation, avionics, engines, flight control, landing gear, hydraulic, electrical, air, communications, etc. The aforementioned example is only indicative of a potential scenario that might provide an initial basis for the preparation of an information security risk assessment that justifies the exclusion of all elements of an organisation from the scope of the ISMS.

GM · GM1 IS.D.OR.200(e) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.D.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.D.OR.200 →

Metis opens with Avioverse in October 2026 · request early access.