Appendix II — Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0
ED Decision 2025/015/R
Part-IS main task |
Activity type |
Reference |
||
Management, |
Part-IS |
EU e-CF |
NIST CSF 2.0 |
|
Competence areas & skills |
Functions & categories |
|||
Establish and operate an information security management system (ISMS) |
Management |
IS.AR.200(a) |
ISM (E.08) |
GV – Govern |
Establish the scope of the ISMS in accordance with Part-IS requirements |
Management |
IS.AR.205(a) |
ISM (E.08) |
GV.RM
– Risk Management Strategy; |
Implement and maintain an information security policy |
Management |
IS.AR.200(a)(1) |
ISM (E.08) |
GV.PO – Policy |
Identify and review information security risks |
Management |
IS.AR.200(a)(2) |
ISM (E.08), Risk Management (E.02) |
GV.SC
– Cybersecurity Supply Chain Risk Management; |
Implement information security risk treatment measures |
Management |
IS.AR.200(a)(3) |
ISM (E.08), Risk Management (E.02) |
ID.RA — Risk Assessment |
Set up measures to detect information security events, identify those that may develop to incidents with a potential impact on aviation safety, and respond to, and recover from, such incidents |
Management |
IS.AR.200(a)(4) |
Incident Management (C.04) |
DE
– Detect; |
Monitor compliance with this Regulation and report findings to top management |
Operational |
IS.AR.200(a)(8) |
Compliance (E.09) |
GV.RR
– Roles, Responsibilities and Authorities; |
Protect confidentiality of exchanged information |
Operational |
IS.AR.200(a)(9) |
Information Security Management (E.08) |
PR.DS
– Data Security; |
Implement and maintain a continuous improvement process to measure the effectiveness and maturity of the ISMS and strive to improve it |
Management |
IS.AR.200(b) |
Information Security Management (E.08) |
GV.OV
– Oversight; |
Communicate to the Agency changes regarding capability and responsibilities |
Operational |
IS.AR.200(a)(10) |
Risk Management (E.02), ISM (E.08) |
GV.OC – Organisational Context (03) |
Share information to assist other competent authorities, agencies and organisations |
Operational |
IS.AR.200(a)(11) |
Risk Management (E.02), ISM (E.08) |
ID.RA
– Risk Assessment (02); |
Document and maintain all key processes, procedures, roles and responsibilities |
Management |
IS.AR.200(c) |
ISM (E.08), Compliance (E.09) |
GV.RR
– Roles, Responsibilities and Authorities; |
Identify all elements which could be exposed to information security risks |
Management |
IS.AR.205(a) |
Risk Management (E.02) |
ID.AM – Asset Management |
Identify the interfaces with other organisations which could result in exposure to information security risks |
Management |
IS.AR.205(b) |
Risk
Management (E.02), |
ID.AM
– Asset Management; |
Identify information security risks and assign a risk level |
Management |
IS.AR.205(c) |
Risk Management (E.02) |
GV.RM
– Risk Management Strategy; |
Review and update the risk assessment based on certain criteria |
Operational |
IS.AR.205(d) |
Risk Management (E.02) |
GV.RM
– Risk Management Strategy; |
Develop and implement measures to address risks and verify their effectiveness |
Operational |
IS.AR.210(a) |
Risk Management (E.02) |
GV.RM
– Risk Management Strategy; |
Communicate the outcome of the risk assessment to management, other personnel and other organisations sharing an interface |
Operational |
IS.AR.210(b) |
Risk Management (E.02), ISM (E.08) |
GV.RM
– Risk Management Strategy; |
Implement measures to detect in processes and operations information security events which may have a potential impact on aviation safety |
Operational |
IS.AR.215(a) |
ISM (E.08) |
DE.CM
– Continuous Monitoring; |
Implement measures to respond to information security events that may cause an information security incident |
Operational |
IS.AR.215(b) |
Incident Management (C.04) |
RS.MA
– Incident Management; |
Implement measures to recover from information security incidents |
Operational |
IS.AR.215(c) |
Incident Management (C.04) |
RC.RP
– Incident Recovery Plan Execution; |
Manage risks associated with contracted activities with regard to the management of information security |
Management |
Supplier Relationship Management (E.10) |
GV.SC – Cybersecurity Supply Chain Risk Management |
|
Define a person with the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this Regulation |
Management |
IS.AR.225(a) |
ISM (E.08), Compliance (E.09) |
GV.RR – Roles, Responsibilities, and Authorities |
Create and maintain a process to ensure that there is sufficient personnel to perform all activities regarding information security management |
Management |
IS.AR.225(b) |
Personnel Development (D.11) |
GV.RR – Roles, Responsibilities, and Authorities |
Create and maintain a process to ensure that the personnel have the necessary competence for activities regarding information security management |
Management |
IS.AR.225(c) |
Personnel Development (D.11) |
GV.RR
– Roles, Responsibilities, and Authorities; |
Create and maintain a process to ensure that the personnel acknowledge the responsibilities associated with the assigned roles and tasks |
Management |
IS.AR.225(d) |
Personnel Development (D.11) |
GV.RR – Roles, Responsibilities, and Authorities |
Verify the identity and trustworthiness of personnel who have access to information systems |
Management |
IS.AR.225(e) |
ISM (E.08) |
GV.RR
– Roles, Responsibilities, and Authorities; |
Archive, protect and retain records and ensure they are traceable for a specified time |
Operational |
ISM (E.08), Compliance (E.09) |
GV.OV
– Oversight; |
|
Regularly assess the effectiveness and maturity of the ISMS |
Operational |
IS.AR.235(a) |
ISM (E.08) |
GV.OV
– Oversight; |
Take actions to improve the ISMS if required. Reassess the ISMS elements affected by the implemented measures. |
Operational |
IS.AR.235(b) |
ISM (E.08) |
GV.OV
– Oversight; |