Law / European Union

Commission Implementing Regulation (EU) 2023/203, Information Security Management System for Aviation Organizations (Part-IS.I.OR)

Commission Implementing Regulation (EU) 2023/203, Annex II

In force since .

A sector security regimes rule binding public and private bodies.

Obligation class
Security, Governance

As of .

What it requires

  • This duty binds the organizations named in Article 2(1) of Commission Implementing Regulation (EU) 2023/203: a Part-145 maintenance organization, a Part-CAMO continuing airworthiness management organization, a Part-ORO air operator, an approved training organization, an aircrew aero-medical center, a flight simulation training device operator, an air traffic controller training organization or aero-medical center, an organization subject to Part-ATM/ANS.OR, or a U-space service provider or single common information service provider, subject to the exceptions Article 2(1) lists. It reaches you if you declare that you are an essential or important entity under Directive (EU) 2022/2555 and you are one of them. The Regulation applies from , and from to the air navigation service provider of the European Geostationary Navigation Overlay Service (Article 16).
  • Set up, implement and maintain an information security management system that sets a policy on information security, identifies and reviews information security risks, defines and implements risk treatment measures, implements internal and external reporting schemes, detects information security events, responds to and recovers from incidents, applies the measures the competent authority notifies, addresses its findings, and monitors your compliance (point IS.I.OR.200(a)).
  • Run a continuous improvement process and document your key processes, procedures, roles and responsibilities (points IS.I.OR.200(b) and (c)).
  • Identify the elements of your organization exposed to information security risks and your interfaces with other organizations, assign each information security risk with a potential impact on aviation safety a level under a predefined classification, and review and update the assessment when the elements, the interfaces, the information used or the lessons from incidents change (points IS.I.OR.205(a) to (d)).
  • Develop measures to address unacceptable risks, implement them in a timely manner, check their continued effectiveness, inform the persons referred to in point IS.I.OR.240(a) and (b) and the other affected personnel of the outcome of the risk assessment, the corresponding threat scenarios and the measures to be implemented, and inform the organizations you share an interface with of any risk you share with them (points IS.I.OR.210(a) and (b)).
  • Establish an internal reporting scheme to collect and evaluate information security events, implement measures to detect incidents and vulnerabilities and to respond to events that may develop into an information security incident, and implement measures to recover from incidents (points IS.I.OR.215 and IS.I.OR.220).
  • After the competent authority notifies findings, identify the root cause or causes, define a corrective action plan and demonstrate the correction to the authority's satisfaction within the period agreed with it (point IS.I.OR.225).
  • When you contract out any part of these activities, ensure that the contracted activities comply with the Regulation, that the contracted organization works under your oversight, and that the risks of the contracted activities are managed (point IS.I.OR.235(a)).
  • Have the accountable manager ensure that the resources needed to comply are available, establish and promote the information security policy, and appoint a person or group of persons to ensure compliance and to manage the compliance monitoring function (points IS.I.OR.240(a) to (c)).
  • Keep archived and traceable records of approvals, contracts, key processes, risks and risk treatment measures, reported incidents and vulnerabilities, and events that may need reassessment, and keep the records of key processes, risks and risk treatment measures, and reported incidents and vulnerabilities for at least 5 years (point IS.I.OR.245).

Who enforces it

Enforcement body

The authority responsible for certifying and overseeing compliance with the Regulation, which is the competent authority designated under the regulation that governs each class of organization it covers (for example the competent authority designated under Annex III (Part-ORO) to Regulation (EU) No 965/2012 for an air operator).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 4(1) of Regulation (EU) 2023/203 requires the organizations referred to in Article 2(1) to comply with the requirements of Annex II (Part-IS.I.OR) to that Regulation. Article 2(1) applies the Regulation to the following classes of organization, subject to the exceptions it lists for organizations solely involved in the activities it names.

The classes are maintenance organizations under Part-145, continuing airworthiness management organizations under Part-CAMO, air operators under Part-ORO, approved training organizations, aircrew aero-medical centers, flight simulation training device operators, air traffic controller training organizations and aero-medical centers, organizations under Part-ATM/ANS.OR, and U-space service providers and single common information service providers.

Point IS.I.OR.200(a) requires the organization to set up, implement and maintain an information security management system with a policy on information security, risk identification and treatment, internal and external reporting schemes, detection of information security events, response to and recovery from incidents, and compliance monitoring. Point IS.I.OR.200(b) requires a continuous improvement process.

Point IS.I.OR.200(e) lets the competent authority approve an organization not to implement these requirements if it demonstrates that its activities, facilities, resources and services pose no information security risks with a potential impact on aviation safety to itself or to other organizations. Point IS.I.OR.205(a) requires the organization to identify all its elements that could be exposed to information security risks.

Point IS.I.OR.205(c) requires the organization to identify the information security risks that may have a potential impact on aviation safety and to assign each risk a level according to a predefined classification. Point IS.I.OR.205(d) requires the organization to review and update the risk assessment when the elements, the interfaces, the information used to classify risks or the lessons learnt from incidents change.

Point IS.I.OR.210(a) requires the organization to develop measures to address unacceptable risks, implement them in a timely manner and check their continued effectiveness. Point IS.I.OR.215(a) requires an internal reporting scheme to collect and evaluate information security events, including those to be reported externally.

Point IS.I.OR.220 requires measures to detect incidents and vulnerabilities, measures to respond to events that may develop into an information security incident, and measures to recover from incidents. Point IS.I.OR.225(a) requires the organization, after the competent authority notifies findings, to identify the root causes, define a corrective action plan and demonstrate the correction to the authority's satisfaction.

Point IS.I.OR.235(a) requires the organization to ensure that the activities it contracts out comply with the Regulation and that the contracted organization works under its oversight. Point IS.I.OR.240(a) requires the accountable manager to ensure that the resources needed to comply are available, to establish and promote the information security policy and to demonstrate a basic understanding of the Regulation.

Point IS.I.OR.245 requires the organization to keep archived and traceable records of approvals, contracts, key processes, risks and risk treatment measures, reported incidents and vulnerabilities, and events that may need reassessment. The records of key processes, of risks and risk treatment measures, and of reported incidents and vulnerabilities are kept for at least 5 years.

The Regulation applies from , and from to the air navigation service provider of the European Geostationary Navigation Overlay Service. Article 5(1) treats compliance with equivalent security requirements laid down in accordance with Article 14 of Directive (EU) 2016/1148 as compliance with this Regulation.

Directive (EU) 2022/2555 repealed Directive (EU) 2016/1148 with effect from , and references to the repealed Directive are construed as references to Directive (EU) 2022/2555. The authority responsible for certifying and overseeing compliance is, for each class of organization, the competent authority designated under the regulation that governs that class (Article 6(1)).

Article 131 of Regulation (EU) 2018/1139 requires Member States to lay down the rules on penalties applicable to infringement of that Regulation and of the delegated and implementing acts adopted on the basis of it. The Regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.

When LexLint raises it

When your app profile says your app runs an essential service.

Back to the example  ·  Lint your app