Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

6.6 Information and cybersecurity

Formal title · GM to Regulation (EU) 2017/373 · EAR revision 26 Jan 2026

IRImplementing rule

6.6Information and cybersecurity

As stipulated in Regulation (EU) 2017/373 [4], ATM/ANS.OR.D.010, ANSPs — and therefore also ATS providers — shall ‘establish a security management system to ensure; (a) the security of their facilities and personnel so as to prevent unlawful interference with the provision of services; and (b) the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised.’ Remote aerodrome ATS relies on IT infrastructure for data exchange to support, amongst others visual surveillance system, communications (in particular aeronautical mobile service and surface movement service) and management of aerodrome equipment/systems/assets, which may render it vulnerable to potential security threats to computer systems or the data exchanged. Risks may be posed due to unavailability of such data (denial of service) or unauthorised modification (data tampering) with limited ATCO/AFISO capability to detect potential integrity problems in the information presented at the RTM. Consequently, the introduction of remote aerodrome ATS may affect the security risk assessment and these security vulnerabilities may have an impact on safety. For this reason, these security vulnerabilities may add new causes to the existing safety hazards (e.g. possible corruption of navigation aids information, loss of visual presentation data) or may add new hazards (e.g. complete loss of the provision of ATS). Based on these considerations, the ATS provider is required (in accordance with Regulation (EU) 2017/373, see above) to conduct a dedicated security risk assessment and take the necessary measures to protect its systems and constituents against information and cybersecurity threats. The results of this security risk assessment should be considered as input to the safety assessment. In this context, security threat is defined as any circumstance or event with the potential to adversely impact on the operation, systems and/or constituents due to human action (accidental, casual, or intentionally or unintentionally mistaken) resulting from unauthorised access, use, disclosure, denial, disruption, modification, or destruction of information and/or information system interfaces. It should be noted that this may also include malware and the effects of external systems on dependent systems.

IR · 6.6 — GM to Regulation (EU) 2017/373 · ED Decision 2023/005/R · Remote ATS Easy Access Rules · EAR revision 26 Jan 2026

All rules in 6. Management of change

Consolidated from the EASA Easy Access Rules (revision 26 Jan 2026, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about 6.6 →

Metis opens with Avioverse in October 2026 · request early access.