8.3 Aviation Information Security Management — EASA Part-IS
Key Takeaways
- Commission Implementing Regulation (EU) 2023/203 (Part-IS.I.OR) and Commission Delegated Regulation (EU) 2022/1645 (Part-IS.D.OR) together establish EASA Part-IS, a mandatory horizontal information security framework across civil aviation.
- Cybersecurity was formally integrated into the EASA Part-66 Module 10 syllabus under Regulation (EU) 2023/989 in June 2024 to address cyber risks in connected, e-Enabled transport aircraft.
- Approved organisations (Part-145, Part-CAMO, Part-21, Part-ORO) must establish an Information Security Management System (ISMS) integrated with their Safety Management System (SMS) to manage digital risks impacting flight safety.
- Field-Loadable Software (FLS) and Loadable Software Aircraft Parts (LSAP) are legally classified as aircraft components requiring digital signatures, cryptographic checksum verification (SHA-256), and release under a Certificate of Release to Service (CRS).
- Connected maintenance laptops, portable data loaders (ARINC 615A) and GSE are direct conduits to the Aircraft Control Domain (ACD), mandating strict endpoint security, a ban on unauthorised USB media, and external reporting to the competent authority within 72 hours under IS.I.OR.230 (IS.D.OR.230 for design, production and aerodrome organisations).
8.3 Aviation Information Security Management — EASA Part-IS
Quick Answer: Commission Implementing Regulation (EU) 2023/203 and Commission Delegated Regulation (EU) 2022/1645 establish the EASA Part-IS (Information Security) regulatory framework. Part-IS.D.OR under Delegated Regulation 2022/1645 applies from 16 October 2025 to design and production organisations and aerodrome operators; Part-IS.I.OR under Implementing Regulation 2023/203 applies from 22 February 2026 to Part-145 maintenance organisations, Part-CAMO, air operators, ATOs and ATM/ANS providers. Added to the EASA Part-66 Module 10 syllabus in the June 2024 update (Regulation (EU) 2023/989), cybersecurity recognizes modern e-Enabled aircraft as highly connected cyber-physical systems. Under Part-IS, organizations must implement an Information Security Management System (ISMS) to manage cybersecurity risks impacting safety. Key airworthiness requirements include treating Field-Loadable Software (FLS) and Loadable Software Aircraft Parts (LSAP) as certified aircraft parts with cryptographic checksum verification per ARINC 615/615A, ensuring navigation database integrity, strictly controlling connected maintenance laptops and Ground Support Equipment (GSE) against malware and unauthorized USB media, and reporting safety-affecting cybersecurity incidents within 72 hours.
For decades, aviation safety focused entirely on physical reliability: structural fatigue, mechanical wear, hydraulic integrity, and aerodynamic performance. However, contemporary commercial airliners—such as the Airbus A350, A380, A320neo, and Boeing 787, 777X, and 737 MAX—are sophisticated cyber-physical systems. They continuously exchange telemetry, software parts, navigation updates, and maintenance data with ground stations, maintenance laptops, and cloud servers. Recognizing that a digital compromise can disable flight controls or corrupt primary navigation as catastrophically as a structural failure, the European Commission enacted the Part-IS framework and formally integrated aviation cybersecurity into the EASA Part-66 Module 10 syllabus in June 2024.
The New European Regulatory Architecture: Part-IS
The European legal foundation for civil aviation cybersecurity consists of two coordinated regulations, and their numbers are a classic examination trap — there is no aviation regulation numbered 2023/204 (that number belongs to a maritime hazardous-goods database instrument):
- Commission Delegated Regulation (EU) 2022/1645 of 14 July 2022, which introduces Part-IS.D.OR for organisations covered by Regulation (EU) No 748/2012 (design and production organisations) and Regulation (EU) No 139/2014 (aerodrome operators and apron management service providers). Article 8 states that it applies from 16 October 2025.
- Commission Implementing Regulation (EU) 2023/203 of 27 October 2022, which introduces Part-IS.AR for competent authorities and Part-IS.I.OR for organisations covered by Regulations (EU) No 1321/2014, (EU) No 965/2012, (EU) No 1178/2011, (EU) 2015/340, (EU) 2017/373 and (EU) 2021/664 — which is what brings Part-145, Part-CAMO, Part-147, air operators and ATM/ANS into scope. It applies from 22 February 2026.
Both annexes run from IS.…OR.100 (Scope) through IS.…OR.260 (Continuous improvement), with the frequently examined points being IS.I.OR.200 (ISMS), IS.I.OR.205 (risk assessment), IS.I.OR.210 (risk treatment), IS.I.OR.215 (internal reporting), IS.I.OR.220 (incident detection, response and recovery), IS.I.OR.230 (external reporting), IS.I.OR.235 (contracting), IS.I.OR.240 (personnel) and IS.I.OR.245 (record-keeping).
Universal Horizontal Applicability
Unlike operational regulations that apply only to airlines, Part-IS is a horizontal regulation that applies across every approved domain in European civil aviation:
- Part-145: Approved Maintenance Organisations;
- Part-CAMO & Part-CAO: Continuing Airworthiness Management Organisations;
- Part-21: Design Organisations (DOA) and Production Organisations (POA);
- Part-147: Approved Maintenance Training Organisations;
- Part-ORO / Part-CAT: Air Operators and Commercial Air Transport carriers;
- Aerodromes (ADR) & ATM/ANS: Airport operators and air traffic navigation service providers.
Mandatory compliance therefore falls in two waves: 16 October 2025 for the Delegated Regulation (EU) 2022/1645 population (DOA, POA, aerodromes) and 22 February 2026 for the Implementing Regulation (EU) 2023/203 population (Part-145, Part-CAMO, Part-147, AOC holders, ATOs, ATM/ANS) and their competent authorities. For a Part-66 certifying engineer, the date that matters is 22 February 2026.
Why Cybersecurity is in EASA Part-66 Module 10: The e-Enabled Aircraft
Under Commission Implementing Regulation (EU) 2023/989 (adopted in June 2024), EASA modernized the Part-66 basic knowledge syllabus. Certifying technicians are no longer just mechanical and electrical specialists—they are the physical gatekeepers of the aircraft's internal digital networks.
Aircraft Network Domain Architecture
Modern transport aircraft divide internal data networks into distinct security domains, separated by hardware firewalls, network routers, and unidirectional data diodes:
| Network Domain | Acronym | Typical Connected Systems | Security & Safety Criticality |
|---|---|---|---|
| Aircraft Control Domain | ACD | Primary flight control computers, FADEC engine controllers, cockpit flight displays, inertial reference units (ADIRU). | Flight Critical (DAL A / Level 1). Highest security integrity. Malicious compromise directly hazards flight safety. |
| Airline Information Services Domain | AISD | Electronic Flight Bags (EFB), Aircraft Tech Log computers, Engine Health Monitoring units, performance computers. | Operational Critical. Supports flight efficiency and administrative operations; interfaces between ACD and ground networks. |
| Passenger Information and Entertainment Services Domain | PIESD | In-flight entertainment (IFE), passenger in-seat power, passenger Wi-Fi routers, cabin lighting/audio networks. | Non-Safety Critical. Open to passenger interaction; strictly isolated from flight-critical systems. |
The Maintenance Threat Vector: Bypassing the Firewall
While the Passenger Domain (PIESD) is heavily firewalled from the Aircraft Control Domain (ACD) to prevent passenger tampering, the maintenance interface is a direct backdoor. When a Part-66 certifying engineer connects a maintenance laptop or portable data loader directly into an ARINC 615A Ethernet port on the flight deck or avionics bay, the technician is plugged directly behind the aircraft's primary perimeter firewalls into the Aircraft Control Domain.
If that maintenance laptop is infected with malware, or if an untrusted USB flash drive is used to transfer software files, malicious code or corrupted firmware can be injected straight into flight-critical avionics. Maintenance personnel are therefore a primary defense line against cyber sabotage.
The Information Security Management System (ISMS)
Under Part-IS, every approved maintenance and continuing airworthiness organization must establish, implement, and maintain an Information Security Management System (ISMS). Just as Safety Management Systems (SMS) manage physical operational hazards, the ISMS manages digital threats across five core pillars:
- Information Security Policy & Objectives: Defining executive commitment, corporate roles, and security accountability.
- Asset Identification & Classification: Cataloging and mapping all digital assets: diagnostic laptops, electronic ground support equipment (GSE), aircraft data loaders, software storage servers, and avionics test benches.
- Threat Modeling & Risk Assessment: Continuously evaluating potential cyber vulnerabilities, attack scenarios, and their potential impact on aircraft airworthiness and flight safety.
- Risk Treatment & Security Controls: Implementing technical and organizational defenses, including multi-factor authentication (MFA), network segregation, full-disk encryption, and rigorous access rights.
- Continuous Assurance & Emergency Incident Response: Performing periodic cyber vulnerability scans, penetration testing, compliance audits, and security drills.
SMS and ISMS Synergy
A critical requirement of Part-IS is the direct integration of the ISMS with the organization's existing Safety Management System (SMS). A cyber risk is not treated merely as an IT inconvenience; if a cyber vulnerability can compromise aircraft instrumentation, flight control laws, or maintenance data integrity, it is categorized as an airworthiness hazard and escalated through the SMS safety risk matrix.
Protection of Aeronautical Data & Data Buses
Digital communication onboard aircraft relies on specialized data bus architectures that require strict protection under Part-IS guidelines:
Avionics Data Buses: ARINC 429 vs ARINC 664 (AFDX)
- ARINC 429: A legacy point-to-point, simplex (unidirectional) broadcast bus using twisted-pair wiring operating at up to 100 kbps. Because ARINC 429 is physically unidirectional from a single transmitter to multiple receivers, it inherently prevents reverse injection of malicious data from receiving nodes, but lacks cryptographic authentication.
- ARINC 664 Part 7 / AFDX (Avionics Full-Duplex Switched Ethernet): Modern airliners (Airbus A380/A350, Boeing 787) use deterministic switched Ethernet networks operating at 10 to 100 Mbps. AFDX creates Virtual Links (VL) with guaranteed bandwidth and deterministic latency. Under Part-IS, AFDX switches implement hardware filtering to prevent denial-of-service (DoS) packet flooding and unauthorized message injection between different criticality domains.
Electronic Flight Bags (EFB) Security
Electronic Flight Bags (EFBs) host performance calculation applications, aeronautical charts, and digital technical logs:
- Hardware Classification: Installed EFBs (Class 3 / installed equipment) vs portable EFBs (Class 1/2 commercial tablets like iPads).
- Software Security: Under EASA AMC 20-25, EFB software is categorized into Type A (static document viewers) and Type B (interactive performance calculators and mass/balance tools). EFB software communicating with aircraft avionics must utilize secure API gateways and unidirectional cross-domain data diodes to prevent portable device malware from affecting flight guidance computers.
Aeronautical Navigation Databases
Aircraft navigation depends on regular digital database uploads: Flight Management System (FMS) navigation data, terrain elevation databases (TAWS/EGPWS), obstacle databases, and airport moving map databases.
- Certified Data Sources: Under Regulation (EU) 2017/373, aeronautical databases must originate exclusively from certified Type 1 or Type 2 Aeronautical Data Service Providers (DAT providers).
- Integrity & Cycle Management: Data must be delivered through secure, encrypted distribution channels with tamper-evident digital seals. The engineer and flight crew must confirm that the database is active and within its valid 28-day AIRAC cycle prior to release.
Critical Airworthiness Areas for Maintenance Certifying Staff
Part-66 certifying engineers must maintain rigorous operational discipline across four critical technical areas:
1. Field-Loadable Software (FLS) & Loadable Software Aircraft Parts (LSAP)
- Software is an Aircraft Part: In modern aviation, software loaded into an avionics computer is legally classified as an aircraft component—termed a Loadable Software Aircraft Part (LSAP). It carries a designated aircraft software part number, must be accompanied by authorized release documentation (such as an EASA Form 1 or approved software delivery certificate), and requires a formal Certificate of Release to Service (CRS) upon loading.
- Loading Standards: Data loading is conducted using standardized protocols: ARINC 615 (using high-speed serial/floppy/PCMCIA media) or modern ARINC 615A (software data loading over high-speed Ethernet buses).
- Cryptographic Authentication: Before committing software to an aircraft computer, certifying personnel must verify the software's authenticity and integrity using digital signatures and cryptographic checksums (e.g., SHA-256 or SHA-512 hashes). The technician must ensure that the hash generated by the data loader exactly matches the hash specified in the manufacturer's engineering release document.
- On-Board Configuration Verification: After software loading is complete, the engineer must interrogate the system through the Central Maintenance Computer (CMC) or On-Board Maintenance System (OMS) to verify that the displayed software part numbers and checksums match the approved configuration baseline before signing the CRS.
2. Connected Maintenance Tools and Ground Support Equipment (GSE)
- Dedicated Maintenance Laptops: Laptops used for aircraft diagnostics, Electronic Tech Log access, or FLS data loading must be strictly dedicated company assets. Personal laptops or devices used for general web browsing and personal email are strictly prohibited from connecting to aircraft buses.
- Endpoint Protection & Encryption: Maintenance laptops must feature active Endpoint Detection and Response (EDR), commercial antivirus definitions updated daily, full-disk encryption, and disabled external wireless interfaces (Bluetooth, ad-hoc Wi-Fi) during aircraft connections.
- The Strict USB Storage Media Ban: Commercial, unencrypted USB thumb drives are the single largest source of industrial malware infections. Under Part-IS procedures, unauthorized portable storage devices are strictly prohibited. Organisations must utilize dedicated, cryptographically locked, and centrally scanned USB media that are restricted by hardware ID whitelisting.
- Secure Supply Chain: Procuring software updates, test equipment firmware, and digital maintenance manuals requires verified chain of custody to prevent counterfeit or maliciously altered digital files from entering the maintenance stream.
3. Mandatory Cybersecurity Incident Reporting (IS.I.OR.230 / IS.D.OR.230)
There is no rule numbered "Part-IS.A.035". The information security external reporting scheme is IS.I.OR.230 in Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203, and IS.D.OR.230 in the Annex (Part-IS.D.OR) to Delegated Regulation (EU) 2022/1645. IS.I.OR.215 / IS.D.OR.215 cover the parallel internal reporting scheme.
Under IS.…OR.230 the organisation must implement a reporting system that meets the requirements of Regulation (EU) No 376/2014 where that Regulation applies to it, and must report information security incidents and vulnerabilities that may represent a significant risk to aviation safety:
- 72-Hour Reporting Mandate: notification to the competent authority as soon as the condition is known, with the report submitted not exceeding 72 hours from the time the condition became known, unless exceptional circumstances prevent this. Reports also go to the design approval holder for an aircraft, or to the design organisation for a system or constituent.
- Follow-up: a follow-up report on the actions taken and intended follows as soon as those actions have been identified.
- Information Exchange: Incident data is submitted to the European Central Repository (ECR) and coordinated with European aviation Computer Security Incident Response Teams (CSIRTs) to alert other operators and maintenance organisations against emerging cyber threats.
Practical Maintenance Scenario: FLS Navigation Loading & Suspect USB Drive
Operational Context
A Part-66 Category B2 certifying engineer is tasked with uploading the new 28-day AIRAC cycle FMS navigation database onto an Airbus A320neo at a line station.
Procedural Protocol under Part-IS:
- Media Authentication: The engineer retrieves the update file from the operator's secure engineering server. A contract line technician offers a personal USB thumb drive containing the file, claiming it was downloaded directly from the airline portal.
- Immediate Rejection: Under Part-IS and company MOE procedures, the engineer immediately rejects the personal USB drive. Uncertified, personal media can harbor hidden autorun malware or compromised boot sectors that can infect the aircraft data bus.
- Controlled Transfer: The engineer uses a company-issued, encrypted, and hardware-authenticated data loading tool that has been scanned on the secure maintenance terminal.
- Cryptographic Verification: Using the ARINC 615A data loader, the engineer checks the digital certificate and validates the cryptographic SHA-256 hash against the Airbus engineering work order. The checksum matches perfectly.
- Upload & Verification: The database is transferred across the onboard Ethernet bus. The engineer verifies on the Multipurpose Control and Display Unit (MCDU) that the active database part number and AIRAC cycle dates (e.g., 04 SEP to 01 OCT 2026) are correctly displayed, and signs the Certificate of Release to Service (CRS) in the Aircraft Technical Log.
EASA Module 10 Examination Tips & Regulatory Traps
- Part-IS Regulatory Citation: Memorize the exact pair: Commission Implementing Regulation (EU) 2023/203 (Part-IS.AR and Part-IS.I.OR, applicable 22 February 2026) and Commission Delegated Regulation (EU) 2022/1645 (Part-IS.D.OR, applicable 16 October 2025). 2023/204 is not an aviation regulation — if it appears as an option, it is a distractor.
- Syllabus Addition: Cybersecurity was formally added to the EASA Part-66 Module 10 syllabus by Regulation (EU) 2023/989 in June 2024.
- Software as an Aircraft Part: Field-Loadable Software (FLS) / LSAP is treated with the same legal status as an avionics LRU—it requires a part number, approved data, and a Certificate of Release to Service (CRS).
- Network Domains: Remember that the Aircraft Control Domain (ACD) has the highest safety criticality, while the Passenger Domain (PIESD) is non-safety critical.
- Connected Maintenance Threat: Maintenance laptops connected via ARINC 615/615A bypass external firewalls, making portable tool cyber-hardening a primary airworthiness defense.
- 72-Hour Reporting Rule: The external reporting point is IS.I.OR.230 (or IS.D.OR.230), not "Part-IS.A.035", and the deadline is 72 hours from the time the condition became known. Internal reporting is IS.I.OR.215 / IS.D.OR.215.
Under the EASA Part-IS regulatory framework established by Implementing Regulation (EU) 2023/203 and Delegated Regulation (EU) 2022/1645, which aviation organisations are required to implement an Information Security Management System (ISMS)?
Why was cybersecurity formally introduced into the EASA Part-66 Module 10 syllabus by the European Commission in the June 2024 update (Regulation (EU) 2023/989)?
Before loading Field-Loadable Software (FLS) onto an aircraft avionics computer using an ARINC 615A data loader, what cryptographic verification step must the certifying technician ensure?
Under the Part-IS external reporting scheme and Regulation (EU) No 376/2014, within what maximum timeline must an approved aviation maintenance organisation report an information security incident that impacts or could impact aviation safety to the Competent Authority?
You've completed this section
Continue exploring other exams