IRImplementing rule
6.6Information and cybersecurity
As stipulated in Regulation (EU) 2017/373 [4], ATM/ANS.OR.D.010, ANSPs — and therefore also ATS providers — shall ‘establish a security management system to ensure; (a) the security of their facilities and personnel so as to prevent unlawful interference with the provision of services; and (b) the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised.’ Remote aerodrome ATS relies on IT infrastructure for data exchange to support, amongst others visual surveillance system, communications (in particular aeronautical mobile service and surface movement service) and management of aerodrome equipment/systems/assets, which may render it vulnerable to potential security threats to computer systems or the data exchanged. Risks may be posed due to unavailability of such data (denial of service) or unauthorised modification (data tampering) with limited ATCO/AFISO capability to detect potential integrity problems in the information presented at the RTM. Consequently, the introduction of remote aerodrome ATS may affect the security risk assessment and these security vulnerabilities may have an impact on safety. For this reason, these security vulnerabilities may add new causes to the existing safety hazards (e.g. possible corruption of navigation aids information, loss of visual presentation data) or may add new hazards (e.g. complete loss of the provision of ATS). Based on these considerations, the ATS provider is required (in accordance with Regulation (EU) 2017/373, see above) to conduct a dedicated security risk assessment and take the necessary measures to protect its systems and constituents against information and cybersecurity threats. The results of this security risk assessment should be considered as input to the safety assessment. In this context, security threat is defined as any circumstance or event with the potential to adversely impact on the operation, systems and/or constituents due to human action (accidental, casual, or intentionally or unintentionally mistaken) resulting from unauthorised access, use, disclosure, denial, disruption, modification, or destruction of information and/or information system interfaces. It should be noted that this may also include malware and the effects of external systems on dependent systems.
IR · 6.6 — GM to Regulation (EU) 2017/373 · ED Decision 2023/005/R · Remote ATS Easy Access Rules · EAR revision 26 Jan 2026