AppendixAppendix
Appendix IIMain tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0
| Part-IS main task | Activity type | Reference | ||
|---|---|---|---|---|
| Management, Operational | Part-IS | EU e-CF | NIST CSF 2.0 | |
| Competence areas & skills | Functions & categories | |||
| Establish and operate an information security management system (ISMS) | Management | IS.AR.200(a) | ISM (E.08) | GV – Govern |
| Establish the scope of the ISMS in accordance with Part-IS requirements | Management | IS.AR.205(a) | ISM (E.08) | GV.RM – Risk Management Strategy; ID.AM – Asset Management; |
| Implement and maintain an information security policy | Management | IS.AR.200(a)(1) | ISM (E.08) | GV.PO – Policy |
| Identify and review information security risks | Management | IS.AR.200(a)(2) IS.AR.205 | ISM (E.08), Risk Management (E.02) | GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment; ID.IM – Improvement |
| Implement information security risk treatment measures | Management | IS.AR.200(a)(3) IS.AR.210 | ISM (E.08), Risk Management (E.02) | ID.RA — Risk Assessment |
| Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidents | Management | IS.AR.200(a)(4) IS.AR.215 | Incident Management (C.04) | DE – Detect; RE – Respond; RC – Recover; PR – Protect (as per Risk Assessment) |
| Monitor compliance with this Regulation and report findings to top management | Operational | IS.AR.200(a)(8) | Compliance (E.09) | GV.RR – Roles, Responsibilities and Authorities; GV.RM – Risk Management; GV.OV – Oversight; ID.IM – Improvement |
| Protect confidentiality of exchanged information | Operational | IS.AR.200(a)(9) | Information Security Management (E.08) | PR.DS – Data Security; Other PR – Protect categories as applicable |
| Implement and maintain a continuous improvement process to measure the effectiveness and maturity of the ISMS and strive to improve it | Management | IS.AR.200(b) IS.AR.235 | Information Security Management (E.08) | GV.OV – Oversight; ID.IM – Improvement |
| Communicate to the Agency changes regarding capability and responsibilities | Operational | IS.AR.200(a)(10) | Risk Management (E.02), ISM (E.08) | GV.OC – Organisational Context (03) |
| Share information to assist other competent authorities, agencies and organisations | Operational | IS.AR.200(a)(11) | Risk Management (E.02), ISM (E.08) | ID.RA – Risk Assessment (02); RS.CO – Incident Response Reporting and Communication |
| Document and maintain all key processes, procedures, roles and responsibilities | Management | IS.AR.200(c) | ISM (E.08), Compliance (E.09) | GV.RR – Roles, Responsibilities and Authorities; Other functions and categories as applicable |
| Identify all elements which could be exposed to information security risks | Management | IS.AR.205(a) | Risk Management (E.02) | ID.AM – Asset Management |
| Identify the interfaces with other organisations which could result in exposure to information security risks | Management | IS.AR.205(b) | Risk Management (E.02), Business Change Management (E.07) | ID.AM – Asset Management; GV.SC – Cybersecurity Supply Chain Risk Management |
| Identify information security risks and assign a risk level | Management | IS.AR.205(c) | Risk Management (E.02) | GV.RM – Risk Management Strategy; ID.RA – Risk Assessment |
| Review and update the risk assessment based on certain criteria | Operational | IS.AR.205(d) | Risk Management (E.02) | GV.RM – Risk Management Strategy; GV.PO – Policy; GV.OV — Oversight; GV.SC – Cybersecurity Supply Chain Risk Management; ID.IM – Improvement |
| Develop and implement measures to address risks and verify their effectiveness | Operational | IS.AR.210(a) | Risk Management (E.02) | GV.RM – Risk Management Strategy; ID.RA – Risk Assessment |
| Communicate the outcome of the risk assessment to management, other personnel and other organisations sharing an interface | Operational | IS.AR.210(b) | Risk Management (E.02), ISM (E.08) | GV.RM – Risk Management Strategy; GV.SC – Cybersecurity Supply Chain Risk Management |
| Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safety | Operational | IS.AR.215(a) | ISM (E.08) | DE.CM – Continuous Monitoring; DE.AE – Adverse Event Analysis; ID.RA – Risk Assessment; PR – Protect (selection of relevant controls as per Risk Assessment) |
| Implement measures to respond to information security events that may cause an information security incident | Operational | IS.AR.215(b) | Incident Management (C.04) | RS.MA – Incident Management; RS.AN – Incident Analysis; RS.MI – Incident Mitigation; RS.CO – Incident Response Reporting and Communication (where applicable); PR – Protect (selection of relevant controls as per Risk Assessment) |
| Implement measures to recover from information security incidents | Operational | IS.AR.215(c) | Incident Management (C.04) | RC.RP – Incident Recovery Plan Execution; RC.CO – Incident Recovery Communication; PR – Protect (selection of relevant controls as per Risk Assessment) |
| Manage risks associated with contracted activities with regard to the management of information security | Management | IS.AR.220 | Supplier Relationship Management (E.10) | GV.SC – Cybersecurity Supply Chain Risk Management |
| Define a person with the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this Regulation | Management | IS.AR.225(a) | ISM (E.08), Compliance (E.09) | GV.RR – Roles, Responsibilities, and Authorities |
| Create and maintain a process to ensure that there is sufficient personnel to perform all activities regarding information security management | Management | IS.AR.225(b) | Personnel Development (D.11) | GV.RR – Roles, Responsibilities, and Authorities |
| Create and maintain a process to ensure that the personnel have the necessary competence for activities regarding information security management | Management | IS.AR.225(c) | Personnel Development (D.11) | GV.RR – Roles, Responsibilities, and Authorities; PR.AT – Awareness and Training (02) |
| Create and maintain a process to ensure that the personnel acknowledge the responsibilities associated with the assigned roles and tasks | Management | IS.AR.225(d) | Personnel Development (D.11) | GV.RR – Roles, Responsibilities, and Authorities |
| Verify the identity and trustworthiness of personnel who have access to information systems | Management | IS.AR.225(e) | ISM (E.08) | GV.RR – Roles, Responsibilities, and Authorities; GV.PO – Policy; PR.AA – Entity Management, Authentication, and Access Control |
| Archive, protect and retain records and ensure they are traceable for a specified time | Operational | IS.AR.230 | ISM (E.08), Compliance (E.09) | GV.OV – Oversight; GV.RR – Roles, Responsibilities, and Authorities; PR.DS – Data Security; PR.PS – Platform Security; RS.AN – Incident Analysis; GV.SC – Cybersecurity Supply Chain Risk Management; ID.RA – Risk Assessment |
| Regularly assess the effectiveness and maturity of the ISMS | Operational | IS.AR.235(a) | ISM (E.08) | GV.OV – Oversight; ID.IM – Improvement |
| Take actions to improve the ISMS if required. Reassess the ISMS elements affected by the implemented measures. | Operational | IS.AR.235(b) | ISM (E.08) | GV.OV – Oversight; ID.IM – Improvement |
APPENDIX · Appendix II — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/015/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025