European Union (EASA Member States)

EASA Part-IS

74 controls. 207 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

74 controls 207 frameworks share controls with it European Union (EASA Member States) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

EASA Part-IS Aviation Information Security Evidence & Implementation Kit

74 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
IS.AR.200Competent Authority Oversight0
IS.AR.205Authority Information Sharing0
IS.AR.210Findings and Corrective Actions37
IS.AR.215Information Security Incident Response110
IS.D.OR.200Information Security Management System1
IS.D.OR.205Information Security Risk Assessment125
IS.D.OR.210Information Security Risk Treatment76
IS.D.OR.215Personnel Requirements0
IS.D.OR.220Information Security Risk Management Process1
IS.D.OR.225External Reporting of Information Security Events113
IS.D.OR.230Internal Reporting Scheme0
IS.I.OR.100Access Control to Aviation Information Systems0
IS.I.OR.110Cryptographic Controls3
IS.I.OR.120Operational Technology and Aircraft Systems0
IS.I.OR.200Information Security Management System1
IS.I.OR.205Information Security Risk Assessment125
IS.I.OR.210Information Security Risk Treatment76
IS.I.OR.215Personnel Requirements0
IS.I.OR.220Information Security Risk Management75
IS.I.OR.225External Reporting111
IS.I.OR.230Internal Reporting Scheme0
IS.OR.200Information Security Management System (ISMS)2
IS.OR.205Information Security Risk Assessment2
IS.OR.210Information Security Risk Treatment2
IS.OR.215Information Security Internal Reporting Scheme0
IS.OR.220Information Security Incidents Detection, Response and Recovery0
IS.OR.225Response to Findings Notified by the Competent Authority0
IS.OR.230Information Security External Reporting0
IS.OR.235Contracting of Information Security Management Activities0
IS.OR.240Personnel Requirements0
IS.OR.245Record-Keeping1
IS.OR.250Information Security Management Manual (ISMM)0
IS.OR.255Changes to the Information Security Management System1
IS.OR.260Continuous Improvement0
ARAnnex I Part-IS.AR: authority requirements under Implementing Regulation (EU) 2023/2030
DORAnnex Part-IS.D.OR: organisation requirements under Delegated Regulation (EU) 2022/16450
GUIDEAMC, GM, appendices and the Task Force guidelines0
IORAnnex II Part-IS.I.OR: organisation requirements under Implementing Regulation (EU) 2023/2030
IS.AR.200IS.AR.200 Information security management system (ISMS) of the competent authority0
IS.AR.205IS.AR.205 Information security risk assessment by the competent authority0
IS.AR.210IS.AR.210 Information security risk treatment by the competent authority0
IS.AR.215IS.AR.215 Information security incidents: detection, response and recovery by the competent authority0
IS.AR.220IS.AR.220 Contracting of information security management activities by the competent authority0
IS.AR.225IS.AR.225 Personnel requirements of the competent authority0
IS.AR.230IS.AR.230 Record-keeping by the competent authority0
IS.AR.235IS.AR.235 Continuous improvement by the competent authority0
IS.D.OR.200IS.D.OR.200 Information security management system (ISMS)0
IS.D.OR.205IS.D.OR.205 Information security risk assessment0
IS.D.OR.210IS.D.OR.210 Information security risk treatment0
IS.D.OR.215IS.D.OR.215 Information security internal reporting scheme0
IS.D.OR.220IS.D.OR.220 Information security incidents: detection, response and recovery0
IS.D.OR.225IS.D.OR.225 Response to findings notified by the competent authority0
IS.D.OR.230IS.D.OR.230 Information security external reporting scheme0
IS.D.OR.235IS.D.OR.235 Contracting of information security management activities0
IS.D.OR.240IS.D.OR.240 Personnel requirements0
IS.D.OR.245IS.D.OR.245 Record-keeping0
IS.D.OR.250IS.D.OR.250 Information security management manual (ISMM)0
IS.D.OR.255IS.D.OR.255 Changes to the information security management system0
IS.D.OR.260IS.D.OR.260 Continuous improvement0
IS.I.OR.200IS.I.OR.200 Information security management system (ISMS)0
IS.I.OR.205IS.I.OR.205 Information security risk assessment0
IS.I.OR.210IS.I.OR.210 Information security risk treatment0
IS.I.OR.215IS.I.OR.215 Information security internal reporting scheme0
IS.I.OR.220IS.I.OR.220 Information security incidents: detection, response and recovery0
IS.I.OR.225IS.I.OR.225 Response to findings notified by the competent authority0
IS.I.OR.230IS.I.OR.230 Information security external reporting scheme0
IS.I.OR.235IS.I.OR.235 Contracting of information security management activities0
IS.I.OR.240IS.I.OR.240 Personnel requirements0
IS.I.OR.245IS.I.OR.245 Record-keeping0
IS.I.OR.250IS.I.OR.250 Information security management manual (ISMM)0
IS.I.OR.255IS.I.OR.255 Changes to the information security management system0
IS.I.OR.260IS.I.OR.260 Continuous improvement0
PKGThe Part-IS package: what it is, what applies from when, and what is held0
SCOPEScope, competent authorities and equivalence (Articles 2, 5, 6 and 7 of Regulation (EU) 2023/203; Articles 2, 4 and 5 of Regulation (EU) 2022/1645)0

Tell me when EASA Part-IS files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • ISMS scope statement
  • Statement of applicability
  • ISMS policy
  • Management review minutes
  • Design documents
  • Build standards
  • Quality policy
  • Quality objectives
  • Risk register
  • Resource plan

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for EASA Part-IS, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition