Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

ANNEX II — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.I.OR]

Implementing Regulation (EU) 2023/203 · Information Security (Part-IS) · Regulations (EU) 2023/203 and 2022/1645 · IS.I.OR.100 – IS.I.OR.260

On this page
  1. IS.I.OR.100 Scope

    This Part establishes the requirements to be met by the organisations referred to in Article 2(1) of this Regulation.

  2. IS.I.OR.200 Information security management system (ISMS)

    In order to achieve the objectives set out in Article 1, the organisation shall set up, implement and maintain an information security management system…

    GM1 IS.I.OR.200 Information security management system (ISMS)

    AMC1 IS.I.OR.200(a)(1) Information security management system (ISMS)

    GM1 IS.I.OR.200(a)(1) Information security management system (ISMS)

    AMC1 IS.I.OR.200(a)(12) Information security management system (ISMS)

    GM1 IS.I.OR.200(a)(12) Information security management system (ISMS)

    AMC1 IS.I.OR.200(a)(13) Information security management system (ISMS)

    AMC1 IS.I.OR.200(c) Information security management system (ISMS)

    GM1 IS.I.OR.200(c) Information security management system (ISMS)

    GM1 IS.I.OR.200(d) Information security management system (ISMS)

    AMC1 IS.I.OR.200(e) Information security management system (ISMS)

    GM1 IS.I.OR.200(e) Information security management system (ISMS)

  3. IS.I.OR.205 Information security risk assessment

    The organisation shall identify all its elements which could be exposed to information security risks.

    GM1 IS.I.OR.205 Information security risk assessment

    AMC1 IS.I.OR.205(a) Information security risk assessment

    GM1 IS.I.OR.205(a) Information security risk assessment

    AMC1 IS.I.OR.205(b) Information security risk assessment

    GM1 IS.I.OR.205(b) Information security risk assessment

    GM2 IS.I.OR.205(b) Information security risk assessment

    AMC1 IS.I.OR.205(c) Information security risk assessment

    GM1 IS.I.OR.205(c) Information security risk assessment

    AMC1 IS.I.OR.205(d) Information security risk assessment

    GM1 IS.I.OR.205(d) Information security risk assessment

    GM2 IS.I.OR.205(d) Information security risk assessment

    AMC1 IS.I.OR.205(e) Information security risk assessment

    GM1 IS.I.OR.205(e) Information security risk assessment

  4. IS.I.OR.210 Information security risk treatment

    The organisation shall develop measures to address unacceptable risks identified in accordance with point IS.I.OR.205, implement them in a timely manner…

    GM1 IS.I.OR.210 Information security risk treatment

    AMC1 IS.I.OR.210(a) Information security risk treatment

  5. IS.I.OR.215 Information security internal reporting scheme

    The organisation shall establish an internal reporting scheme to enable the collection and evaluation of information security events, including those to…

    AMC1 IS.I.OR.215(a) &(b) Information security internal reporting scheme

    GM1 IS.I.OR.215(a) &(b) Information security internal reporting scheme

    GM2 IS.I.OR.215(a) &(b) Information security internal reporting scheme

    GM3 IS.I.OR.215(a) &(b) Information security internal reporting scheme

    GM1 IS.I.OR.215(c) Information security internal reporting scheme

    GM1 IS.I.OR.215(d) Information security internal reporting scheme

  6. IS.I.OR.220 Information security incidents — detection, response and recovery

    Based on the outcome of the risk assessment carried out in accordance with point IS.I.OR.205 and the outcome of the risk treatment performed in…

    GM1 IS.I.OR.220 Information security incidents — detection, response and recovery

    AMC1 IS.I.OR.220(a) Information security incidents — detection, response and recovery

    GM1 IS.I.OR.220(a) Information security incidents — detection, response and recovery

    AMC1 IS.I.OR.220(b) Information security incidents — detection, response and recovery

    GM1 IS.I.OR.220(b) Information security incidents — detection, response and recovery

    AMC1 IS.I.OR.220(c) Information security incidents — detection, response and recovery

    GM1 IS.I.OR.220(b) &(c) Information security incidents — detection, response and recovery

    GM1 IS.I.OR.220(c) Information security incidents — detection, response and recovery

  7. IS.I.OR.225 Response to findings notified by the competent authority

    After receipt of the notification of findings submitted by the competent authority, the organisation shall:

    AMC1 IS.I.OR.225 Response to findings notified by the competent authority

    GM1 IS.I.OR.225 Response to findings notified by the competent authority

  8. IS.I.OR.230 Information security external reporting scheme

    The organisation shall implement an information security reporting system that complies with the requirements laid down in Regulation (EU) No 376/2014…

    GM1 IS.I.OR.230 Information security external reporting scheme

    AMC1 IS.I.OR.230(a) &(b) Information security external reporting scheme

    GM1 IS.I.OR.230(a) &(b) Information security external reporting scheme

    AMC1 IS.I.OR.230(c) Information security external reporting scheme

    GM1 IS.I.OR.230(c) Information security external reporting scheme

  9. IS.I.OR.235 Contracting of information security management activities

    The organisation shall ensure that when contracting any part of the activities referred to in point IS.I.OR.200 to other organisations, the contracted…

    GM1 IS.I.OR.235 Contracting of information security management activities

    GM2 IS.I.OR.235 Contracting of information security management activities

    GM3 IS.I.OR.235 Contracting of information security management activities

    AMC1 IS.I.OR.235(a) Contracting of information security management activities

    GM1 IS.I.OR.235(a) Contracting of information security management activities

    GM2 IS.I.OR.235(a) Contracting of information security management activities

    AMC1 IS.I.OR.235(b) Contracting of information security management activities

    GM1 IS.I.OR.235(b) Contracting of information security management activities

  10. IS.I.OR.240 Personnel requirements

    The accountable manager of the organisation designated in accordance with Regulations (EU) No 1321/2014, (EU) No 965/2012, (EU) No 1178/2011, (EU)…

    GM1 IS.I.OR.240 Personnel requirements

    AMC1 IS.I.OR.240(a)(2) Personnel requirements

    AMC1 IS.I.OR.240(a)(3) Personnel requirements

    GM1 IS.I.OR.240(a)(3) Personnel requirements

    AMC1 IS.I.OR.240(b) Personnel requirements

    GM1 IS.I.OR.240(b) Personnel requirements

    GM1 IS.I.OR.240(b) &(c) Personnel requirements

    GM1 IS.I.OR.240(c) Personnel requirements

    AMC1 IS.I.OR.240(d) Personnel requirements

    GM1 IS.I.OR.240(e) Personnel requirements

    AMC1 IS.I.OR.240(f) Personnel requirements

    GM1 IS.I.OR.240(f) Personnel requirements

    AMC1 IS.I.OR.240(g) Personnel requirements

    GM1 IS.I.OR.240(g) Personnel requirements

    AMC1 IS.I.OR.240(h) Personnel requirements

    GM1 IS.I.OR.240(h) Personnel requirements

    AMC1 IS.I.OR.240(i) Personnel requirements

    GM1 IS.I.OR.240(i) Personnel requirements

  11. IS.I.OR.245 Record-keeping

    The organisation shall keep records of its information security management activities (1) The organisation shall ensure that the following records are…

    GM1 IS.I.OR.245 Record-keeping

    AMC1 IS.I.OR.245(a)(1)(vi) &(a)(5) Record-keeping

    GM1 IS.I.OR.245(a)(1)(vi) &(a)(5) Record-keeping

    AMC1 IS.I.OR.245(c) &(d) Record-keeping

    GM1 IS.I.OR.245(c) &(d) Record-keeping

  12. IS.I.OR.250 Information security management manual (ISMM)

    The organisation shall make available to the competent authority an information security management manual (ISMM) and, where applicable, any referenced…

    GM1 IS.I.OR.250(a) Information security management manual (ISMM)

  13. IS.I.OR.255 Changes to the information security management system

    Changes to the ISMS may be managed and notified to the competent authority in a procedure developed by the organisation.

    AMC1 IS.I.OR.255 Changes to the information security management system

    GM1 IS.I.OR.255 Changes to the information security management system

    GM2 IS.I.OR.255 Changes to the information security management system

  14. IS.I.OR.260 Continuous improvement

    The organisation shall assess, using adequate performance indicators, the effectiveness and maturity of the ISMS.

    AMC1 IS.I.OR.260 Continuous improvement

    GM1 IS.I.OR.260 Continuous improvement

    AMC1 IS.I.OR.260(a) Continuous improvement

    GM1 IS.I.OR.260(a) Continuous improvement

    AMC1 IS.I.OR.260(b) Continuous improvement

    GM1 IS.I.OR.260(b) Continuous improvement

  15. Appendix I Examples of threat scenarios with a potential harmful impact on safety

    The following is a non-exhaustive list of examples of information security threat scenarios with a potential harmful impact on safety that may be…

  16. Appendix II Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and NIST CSF 2.0

    Part-IS main task Activity type Reference Management, Operational Part-IS EU e-CF NIST CSF 2.0 Competence areas &

  17. Appendix III Examples of aviation services and interfaces

    AVIATION SERVICES The following is a non-exhaustive and non-complete list of aviation services that can be used as a basis to identify the scope of the…

  18. Appendix IV Part-IS requirements mapping to ISO/IEC 27001:2022 clauses and controls, and considerations on differences

    Although Part-IS does not credit ISO/IEC 27001 certification, the practices and methods typically adopted for implementing and maintaining an ISMS under…

  19. Appendix V Proportionality considerations related to indicators of complexity

    The following is a non-exhaustive, non-binding, list of activities related to the implementation of the ISMS under this Regulation.

  20. Appendix VI Adaptation of the EU Cybersecurity Skills Framework (ECSF)

    [Figure or form omitted from this preview — available in the Avioverse workspace library.]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.I.OR.100 – IS.I.OR.260 →

Metis opens with Avioverse in October 2026 · request early access.

ShareLinkedInX