IS.AR.200 | Competent Authority Oversight | 0 |
IS.AR.205 | Authority Information Sharing | 0 |
IS.AR.210 | Findings and Corrective Actions | 37 |
IS.AR.215 | Information Security Incident Response | 110 |
IS.D.OR.200 | Information Security Management System | 1 |
IS.D.OR.205 | Information Security Risk Assessment | 125 |
IS.D.OR.210 | Information Security Risk Treatment | 76 |
IS.D.OR.215 | Personnel Requirements | 0 |
IS.D.OR.220 | Information Security Risk Management Process | 1 |
IS.D.OR.225 | External Reporting of Information Security Events | 113 |
IS.D.OR.230 | Internal Reporting Scheme | 0 |
IS.I.OR.100 | Access Control to Aviation Information Systems | 0 |
IS.I.OR.110 | Cryptographic Controls | 3 |
IS.I.OR.120 | Operational Technology and Aircraft Systems | 0 |
IS.I.OR.200 | Information Security Management System | 1 |
IS.I.OR.205 | Information Security Risk Assessment | 125 |
IS.I.OR.210 | Information Security Risk Treatment | 76 |
IS.I.OR.215 | Personnel Requirements | 0 |
IS.I.OR.220 | Information Security Risk Management | 75 |
IS.I.OR.225 | External Reporting | 111 |
IS.I.OR.230 | Internal Reporting Scheme | 0 |
IS.OR.200 | Information Security Management System (ISMS) | 2 |
IS.OR.205 | Information Security Risk Assessment | 2 |
IS.OR.210 | Information Security Risk Treatment | 2 |
IS.OR.215 | Information Security Internal Reporting Scheme | 0 |
IS.OR.220 | Information Security Incidents Detection, Response and Recovery | 0 |
IS.OR.225 | Response to Findings Notified by the Competent Authority | 0 |
IS.OR.230 | Information Security External Reporting | 0 |
IS.OR.235 | Contracting of Information Security Management Activities | 0 |
IS.OR.240 | Personnel Requirements | 0 |
IS.OR.245 | Record-Keeping | 1 |
IS.OR.250 | Information Security Management Manual (ISMM) | 0 |
IS.OR.255 | Changes to the Information Security Management System | 1 |
IS.OR.260 | Continuous Improvement | 0 |
AR | Annex I Part-IS.AR: authority requirements under Implementing Regulation (EU) 2023/203 | 0 |
DOR | Annex Part-IS.D.OR: organisation requirements under Delegated Regulation (EU) 2022/1645 | 0 |
GUIDE | AMC, GM, appendices and the Task Force guidelines | 0 |
IOR | Annex II Part-IS.I.OR: organisation requirements under Implementing Regulation (EU) 2023/203 | 0 |
IS.AR.200 | IS.AR.200 Information security management system (ISMS) of the competent authority | 0 |
IS.AR.205 | IS.AR.205 Information security risk assessment by the competent authority | 0 |
IS.AR.210 | IS.AR.210 Information security risk treatment by the competent authority | 0 |
IS.AR.215 | IS.AR.215 Information security incidents: detection, response and recovery by the competent authority | 0 |
IS.AR.220 | IS.AR.220 Contracting of information security management activities by the competent authority | 0 |
IS.AR.225 | IS.AR.225 Personnel requirements of the competent authority | 0 |
IS.AR.230 | IS.AR.230 Record-keeping by the competent authority | 0 |
IS.AR.235 | IS.AR.235 Continuous improvement by the competent authority | 0 |
IS.D.OR.200 | IS.D.OR.200 Information security management system (ISMS) | 0 |
IS.D.OR.205 | IS.D.OR.205 Information security risk assessment | 0 |
IS.D.OR.210 | IS.D.OR.210 Information security risk treatment | 0 |
IS.D.OR.215 | IS.D.OR.215 Information security internal reporting scheme | 0 |
IS.D.OR.220 | IS.D.OR.220 Information security incidents: detection, response and recovery | 0 |
IS.D.OR.225 | IS.D.OR.225 Response to findings notified by the competent authority | 0 |
IS.D.OR.230 | IS.D.OR.230 Information security external reporting scheme | 0 |
IS.D.OR.235 | IS.D.OR.235 Contracting of information security management activities | 0 |
IS.D.OR.240 | IS.D.OR.240 Personnel requirements | 0 |
IS.D.OR.245 | IS.D.OR.245 Record-keeping | 0 |
IS.D.OR.250 | IS.D.OR.250 Information security management manual (ISMM) | 0 |
IS.D.OR.255 | IS.D.OR.255 Changes to the information security management system | 0 |
IS.D.OR.260 | IS.D.OR.260 Continuous improvement | 0 |
IS.I.OR.200 | IS.I.OR.200 Information security management system (ISMS) | 0 |
IS.I.OR.205 | IS.I.OR.205 Information security risk assessment | 0 |
IS.I.OR.210 | IS.I.OR.210 Information security risk treatment | 0 |
IS.I.OR.215 | IS.I.OR.215 Information security internal reporting scheme | 0 |
IS.I.OR.220 | IS.I.OR.220 Information security incidents: detection, response and recovery | 0 |
IS.I.OR.225 | IS.I.OR.225 Response to findings notified by the competent authority | 0 |
IS.I.OR.230 | IS.I.OR.230 Information security external reporting scheme | 0 |
IS.I.OR.235 | IS.I.OR.235 Contracting of information security management activities | 0 |
IS.I.OR.240 | IS.I.OR.240 Personnel requirements | 0 |
IS.I.OR.245 | IS.I.OR.245 Record-keeping | 0 |
IS.I.OR.250 | IS.I.OR.250 Information security management manual (ISMM) | 0 |
IS.I.OR.255 | IS.I.OR.255 Changes to the information security management system | 0 |
IS.I.OR.260 | IS.I.OR.260 Continuous improvement | 0 |
PKG | The Part-IS package: what it is, what applies from when, and what is held | 0 |
SCOPE | Scope, competent authorities and equivalence (Articles 2, 5, 6 and 7 of Regulation (EU) 2023/203; Articles 2, 4 and 5 of Regulation (EU) 2022/1645) | 0 |