AviationBot
Navigate / EASA / INFORMATION SECURITY DEC 2025 / Implementing Regulation (EU) 2023/203 / ANNEX I -- INFORMATION SECURITY -- AUTHORITY REQUIREMENTS [PART-IS.AR] /

Appendix II -- Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

Appendix II maps Part-IS main tasks to EU e-CF competences and NIST CSF 2.0 functions, covering ISMS establishment, risk management, incident response, and personnel duties.

Frequently Asked Questions

The main task 'Manage risks associated with contracted activities with regard to the management of information security' is mapped to EU e-CF competence 'Supplier Relationship Management (E.10)' and NIST CSF 2.0 category 'GV.SC - Cybersecurity Supply Chain Risk Management'. The reference is IS.AR.220.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safety' (IS.AR.215(a)) is mapped to NIST CSF 2.0 categories DE.CM (Continuous Monitoring), DE.AE (Adverse Event Analysis), ID.RA (Risk Assessment), and PR - Protect (selection of relevant controls as per Risk Assessment).

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Communicate to the Agency changes regarding capability and responsibilities' is referenced as IS.AR.200(a)(10). It is mapped to EU e-CF competences Risk Management (E.02) and ISM (E.08), and NIST CSF 2.0 category GV.OC - Organisational Context.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Archive, protect and retain records and ensure they are traceable for a specified time' (IS.AR.230) is mapped to NIST CSF 2.0 categories GV.OV (Oversight), GV.RR (Roles, Responsibilities, and Authorities), PR.DS (Data Security), PR.PS (Platform Security), RS.AN (Incident Analysis), GV.SC (Cybersecurity Supply Chain Risk Management), and ID.RA (Risk Assessment).

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Verify the identity and trustworthiness of personnel who have access to information systems' (IS.AR.225(e)) is mapped to EU e-CF competence 'Information Security Management (E.08)'. It also maps to NIST CSF 2.0 categories GV.RR, GV.PO, and PR.AA.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Review and update the risk assessment based on certain criteria' (IS.AR.205(d)) is mapped to NIST CSF 2.0 categories GV.RM (Risk Management Strategy), GV.PO (Policy), GV.OV (Oversight), GV.SC (Cybersecurity Supply Chain Risk Management), and ID.IM (Improvement).

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidents' (IS.AR.200(a)(4) and IS.AR.215) is mapped to EU e-CF competence 'Incident Management (C.04)'. Also, the tasks under IS.AR.215(b) and IS.AR.215(c) are mapped to Incident Management (C.04).

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The task 'Implement measures to recover from information security incidents' (IS.AR.215(c)) is mapped to NIST CSF 2.0 categories RC.RP (Incident Recovery Plan Execution), RC.CO (Incident Recovery Communication), and PR - Protect (selection of relevant controls as per Risk Assessment).

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

EASA Logo
Appendix II — Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

ED Decision 2025/015/R

Part-IS main task

Activity type

Reference

Management,
Operational

Part-IS

EU e-CF

NIST CSF 2.0

Competence areas & skills

Functions & categories

Establish and operate an information security management system (ISMS)

Management

IS.AR.200(a)

ISM (E.08)

GV – Govern

Establish the scope of the ISMS in accordance with Part-IS requirements

Management

IS.AR.205(a)

ISM (E.08)

GV.RM – Risk Management Strategy;
ID.AM – Asset Management;

Implement and maintain an information security policy

Management

IS.AR.200(a)(1)

ISM (E.08)

GV.PO – Policy

Identify and review information security risks

Management

IS.AR.200(a)(2)
IS.AR.205

ISM (E.08), Risk Management (E.02)

GV.SC – Cybersecurity Supply Chain Risk Management;
ID.RA – Risk Assessment;
ID.IM – Improvement

Implement information security risk treatment measures

Management

IS.AR.200(a)(3)
IS.AR.210

ISM (E.08), Risk Management (E.02)

ID.RA — Risk Assessment

Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidents

Management

IS.AR.200(a)(4)
IS.AR.215

Incident Management (C.04)

DE – Detect;
RE – Respond;
RC – Recover;
PR – Protect (as per Risk Assessment)

Monitor compliance with this Regulation and report findings to top management

Operational

IS.AR.200(a)(8)

Compliance (E.09)

GV.RR – Roles, Responsibilities and Authorities;
GV.RM – Risk Management;
GV.OV – Oversight;
ID.IM – Improvement

Protect confidentiality of exchanged information

Operational

IS.AR.200(a)(9)

Information Security Management (E.08)

PR.DS – Data Security;
Other PR – Protect categories as applicable

Implement and maintain a continuous improvement process to measure the effectiveness and maturity of the ISMS and strive to improve it

Management

IS.AR.200(b)
IS.AR.235

Information Security Management (E.08)

GV.OV – Oversight;
ID.IM – Improvement

Communicate to the Agency changes regarding capability and responsibilities

Operational

IS.AR.200(a)(10)

Risk Management (E.02), ISM (E.08)

GV.OC – Organisational Context (03)

Share information to assist other competent authorities, agencies and organisations

Operational

IS.AR.200(a)(11)

Risk Management (E.02), ISM (E.08)

ID.RA – Risk Assessment (02);
RS.CO – Incident Response Reporting and Communication

Document and maintain all key processes, procedures, roles and responsibilities

Management

IS.AR.200(c)

ISM (E.08), Compliance (E.09)

GV.RR – Roles, Responsibilities and Authorities;
Other functions and categories as applicable

Identify all elements which could be exposed to information security risks

Management

IS.AR.205(a)

Risk Management (E.02)

ID.AM – Asset Management

Identify the interfaces with other organisations which could result in exposure to information security risks

Management

IS.AR.205(b)

Risk Management (E.02),
Business Change Management (E.07)

ID.AM – Asset Management;
GV.SC – Cybersecurity Supply Chain Risk Management

Identify information security risks and assign a risk level

Management

IS.AR.205(c)

Risk Management (E.02)

GV.RM – Risk Management Strategy;
ID.RA – Risk Assessment

Review and update the risk assessment based on certain criteria

Operational

IS.AR.205(d)

Risk Management (E.02)

GV.RM – Risk Management Strategy;
GV.PO – Policy;
GV.OV — Oversight;
GV.SC – Cybersecurity Supply Chain Risk Management;
ID.IM – Improvement

Develop and implement measures to address risks and verify their effectiveness

Operational

IS.AR.210(a)

Risk Management (E.02)

GV.RM – Risk Management Strategy;
ID.RA – Risk Assessment

Communicate the outcome of the risk assessment to management, other personnel and other organisations sharing an interface

Operational

IS.AR.210(b)

Risk Management (E.02), ISM (E.08)

GV.RM – Risk Management Strategy;
GV.SC – Cybersecurity Supply Chain Risk Management

Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safety

Operational

IS.AR.215(a)

ISM (E.08)

DE.CM – Continuous Monitoring;
DE.AE – Adverse Event Analysis;
ID.RA – Risk Assessment;
PR – Protect (selection of relevant controls as per Risk Assessment)

Implement measures to respond to information security events that may cause an information security incident

Operational

IS.AR.215(b)

Incident Management (C.04)

RS.MA – Incident Management;
R
S.AN – Incident Analysis;
RS.MI – Incident Mitigation;
RS.CO – Incident Response Reporting and Communication (where applicable);
PR – Protect (selection of relevant controls as per Risk Assessment)

Implement measures to recover from information security incidents

Operational

IS.AR.215(c)

Incident Management (C.04)

RC.RP – Incident Recovery Plan Execution;
RC.CO – Incident Recovery Communication;
PR – Protect (selection of relevant controls as per Risk Assessment)

Manage risks associated with contracted activities with regard to the management of information security

Management

IS.AR.220

Supplier Relationship Management (E.10)

GV.SC – Cybersecurity Supply Chain Risk Management

Define a person with the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this Regulation

Management

IS.AR.225(a)

ISM (E.08), Compliance (E.09)

GV.RR – Roles, Responsibilities, and Authorities

Create and maintain a process to ensure that there is sufficient personnel to perform all activities regarding information security management

Management

IS.AR.225(b)

Personnel Development (D.11)

GV.RR – Roles, Responsibilities, and Authorities

Create and maintain a process to ensure that the personnel have the necessary competence for activities regarding information security management

Management

IS.AR.225(c)

Personnel Development (D.11)

GV.RR – Roles, Responsibilities, and Authorities;
PR.AT – Awareness and Training (02)

Create and maintain a process to ensure that the personnel acknowledge the responsibilities associated with the assigned roles and tasks

Management

IS.AR.225(d)

Personnel Development (D.11)

GV.RR – Roles, Responsibilities, and Authorities

Verify the identity and trustworthiness of personnel who have access to information systems

Management

IS.AR.225(e)

ISM (E.08)

GV.RR – Roles, Responsibilities, and Authorities;
GV.PO – Policy;
PR.AA – Entity Management, Authentication, and Access Control

Archive, protect and retain records and ensure they are traceable for a specified time

Operational

IS.AR.230

ISM (E.08), Compliance (E.09)

GV.OV – Oversight;
GV.RR – Roles, Responsibilities, and Authorities;
PR.DS – Data Security;
PR.PS – Platform Security;
RS.AN – Incident Analysis;
GV.SC – Cybersecurity Supply Chain Risk Management;
ID.RA – Risk Assessment

Regularly assess the effectiveness and maturity of the ISMS

Operational

IS.AR.235(a)

ISM (E.08)

GV.OV – Oversight;
ID.IM – Improvement

Take actions to improve the ISMS if required. Reassess the ISMS elements affected by the implemented measures.

Operational

IS.AR.235(b)

ISM (E.08)

GV.OV – Oversight;
ID.IM – Improvement



AI for Aviation Professionals

Aviation.Bot is an AI tool that assists you with aviation compliance.