Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

Appendix II Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

AppendixAppendix

Appendix IIMain tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

Part-IS main taskActivity typeReference
Management, OperationalPart-ISEU e-CFNIST CSF 2.0
Competence areas & skillsFunctions & categories
Establish and operate an information security management system (ISMS)ManagementIS.AR.200(a)ISM (E.08)GV – Govern
Establish the scope of the ISMS in accordance with Part-IS requirementsManagementIS.AR.205(a)ISM (E.08)GV.RM – Risk Management Strategy; ID.AM – Asset Management;
Implement and maintain an information security policyManagementIS.AR.200(a)(1)ISM (E.08)GV.PO – Policy
Identify and review information security risksManagementIS.AR.200(a)(2) IS.AR.205ISM (E.08), Risk Management (E.02)GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment; ID.IM – Improvement
Implement information security risk treatment measuresManagementIS.AR.200(a)(3) IS.AR.210ISM (E.08), Risk Management (E.02)ID.RA — Risk Assessment
Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidentsManagementIS.AR.200(a)(4) IS.AR.215Incident Management (C.04)DE – Detect; RE – Respond; RC – Recover; PR – Protect (as per Risk Assessment)
Monitor compliance with this Regulation and report findings to top managementOperationalIS.AR.200(a)(8)Compliance (E.09)GV.RR – Roles, Responsibilities and Authorities; GV.RM – Risk Management; GV.OV – Oversight; ID.IM – Improvement
Protect confidentiality of exchanged informationOperationalIS.AR.200(a)(9)Information Security Management (E.08)PR.DS – Data Security; Other PR – Protect categories as applicable
Implement and maintain a continuous improvement process to measure the effectiveness and maturity of the ISMS and strive to improve itManagementIS.AR.200(b) IS.AR.235Information Security Management (E.08)GV.OV – Oversight; ID.IM – Improvement
Communicate to the Agency changes regarding capability and responsibilitiesOperationalIS.AR.200(a)(10)Risk Management (E.02), ISM (E.08)GV.OC – Organisational Context (03)
Share information to assist other competent authorities, agencies and organisationsOperationalIS.AR.200(a)(11)Risk Management (E.02), ISM (E.08)ID.RA – Risk Assessment (02); RS.CO – Incident Response Reporting and Communication
Document and maintain all key processes, procedures, roles and responsibilitiesManagementIS.AR.200(c)ISM (E.08), Compliance (E.09)GV.RR – Roles, Responsibilities and Authorities; Other functions and categories as applicable
Identify all elements which could be exposed to information security risksManagementIS.AR.205(a)Risk Management (E.02)ID.AM – Asset Management
Identify the interfaces with other organisations which could result in exposure to information security risksManagementIS.AR.205(b)Risk Management (E.02), Business Change Management (E.07)ID.AM – Asset Management; GV.SC – Cybersecurity Supply Chain Risk Management
Identify information security risks and assign a risk levelManagementIS.AR.205(c)Risk Management (E.02)GV.RM – Risk Management Strategy; ID.RA – Risk Assessment
Review and update the risk assessment based on certain criteriaOperationalIS.AR.205(d)Risk Management (E.02)GV.RM – Risk Management Strategy; GV.PO – Policy; GV.OV — Oversight; GV.SC – Cybersecurity Supply Chain Risk Management; ID.IM – Improvement
Develop and implement measures to address risks and verify their effectivenessOperationalIS.AR.210(a)Risk Management (E.02)GV.RM – Risk Management Strategy; ID.RA – Risk Assessment
Communicate the outcome of the risk assessment to management, other personnel and other organisations sharing an interfaceOperationalIS.AR.210(b)Risk Management (E.02), ISM (E.08)GV.RM – Risk Management Strategy; GV.SC – Cybersecurity Supply Chain Risk Management
Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safetyOperationalIS.AR.215(a)ISM (E.08)DE.CM – Continuous Monitoring; DE.AE – Adverse Event Analysis; ID.RA – Risk Assessment; PR – Protect (selection of relevant controls as per Risk Assessment)
Implement measures to respond to information security events that may cause an information security incidentOperationalIS.AR.215(b)Incident Management (C.04)RS.MA – Incident Management; RS.AN – Incident Analysis; RS.MI – Incident Mitigation; RS.CO – Incident Response Reporting and Communication (where applicable); PR – Protect (selection of relevant controls as per Risk Assessment)
Implement measures to recover from information security incidentsOperationalIS.AR.215(c)Incident Management (C.04)RC.RP – Incident Recovery Plan Execution; RC.CO – Incident Recovery Communication; PR – Protect (selection of relevant controls as per Risk Assessment)
Manage risks associated with contracted activities with regard to the management of information securityManagementIS.AR.220Supplier Relationship Management (E.10)GV.SC – Cybersecurity Supply Chain Risk Management
Define a person with the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this RegulationManagementIS.AR.225(a)ISM (E.08), Compliance (E.09)GV.RR – Roles, Responsibilities, and Authorities
Create and maintain a process to ensure that there is sufficient personnel to perform all activities regarding information security managementManagementIS.AR.225(b)Personnel Development (D.11)GV.RR – Roles, Responsibilities, and Authorities
Create and maintain a process to ensure that the personnel have the necessary competence for activities regarding information security managementManagementIS.AR.225(c)Personnel Development (D.11)GV.RR – Roles, Responsibilities, and Authorities; PR.AT – Awareness and Training (02)
Create and maintain a process to ensure that the personnel acknowledge the responsibilities associated with the assigned roles and tasksManagementIS.AR.225(d)Personnel Development (D.11)GV.RR – Roles, Responsibilities, and Authorities
Verify the identity and trustworthiness of personnel who have access to information systemsManagementIS.AR.225(e)ISM (E.08)GV.RR – Roles, Responsibilities, and Authorities; GV.PO – Policy; PR.AA – Entity Management, Authentication, and Access Control
Archive, protect and retain records and ensure they are traceable for a specified timeOperationalIS.AR.230ISM (E.08), Compliance (E.09)GV.OV – Oversight; GV.RR – Roles, Responsibilities, and Authorities; PR.DS – Data Security; PR.PS – Platform Security; RS.AN – Incident Analysis; GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment
Regularly assess the effectiveness and maturity of the ISMSOperationalIS.AR.235(a)ISM (E.08)GV.OV – Oversight; ID.IM – Improvement
Take actions to improve the ISMS if required. Reassess the ISMS elements affected by the implemented measures.OperationalIS.AR.235(b)ISM (E.08)GV.OV – Oversight; ID.IM – Improvement

APPENDIX · Appendix II — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/015/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about Appendix II →

Metis opens with Avioverse in October 2026 · request early access.