Skip to main content
Image coming soon

EASA Part-IS Aviation Information Security Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
EASA Part-IS · Aviation Information Security · Evidence & Implementation Kit
Meet EASA Part-IS, without decoding two EU regulations into an information security management system yourself.
Every Part-IS requirement, from the ISMS and risk assessment through detection, incident response and mandatory reporting to your competent authority, handed to you as an adopt-ready requirement with the evidence an authority examines.
Authority-ready in a weekend, not a quarter.

Here is the honest situation. Part-IS is the new EU requirement that aviation organisations manage information security risks with a potential impact on aviation safety. It applies across design and production organisations, operators, maintenance, CAMOs and training organisations, and it must integrate with your existing management system. The requirements are clear once decoded, an ISMS, risk assessment and treatment, event detection, incident response, and mandatory reporting to the competent authority. Decoding two regulations and evidencing each requirement is the work, and a gap in reporting or risk treatment is what an authority raises.

This Kit removes that decode. It is every Part-IS requirement written as an adopt-ready control you personalize in a weekend, integrated with your existing safety management system.

What you get, the moment you buy

32
Requirements as adopt-ready controls. Every Part-IS provision, from the ISMS and risk assessment through detection, incident response, reporting and contracting, written so you personalize and apply it. The safety-impact scoping is built in.
32
Evidence-they-examine checklists. For each requirement, exactly what your competent authority examines, plus the finding they most often raise, so you close it before oversight.
1
Part-IS Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record status and evidence location, aligned to your management system.
1
Gap & Readiness Assessment. Score each requirement and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the EASA Part-IS requirement structure of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203, with the aviation-safety scoping and competent-authority reporting called out. Editable Word and Excel files.

Built to sit inside your existing management system
Part-IS is not a bolt-on. It must integrate with the safety and management system you already run. This Kit writes each requirement so it slots into that system, and evidences it the way an authority audit expects, so you extend what you have rather than build a parallel program.

What one control looks like

This is the requirement to establish and maintain the ISMS, the backbone of Part-IS. All 32 are built to this depth.

ISOR-1 Establish and maintain the ISMS ISMS
Meet this requirement

[Organization] shall establish, implement, maintain and continuously improve an information security management system covering all activities, facilities and personnel whose compromise could have a potential impact on aviation safety. The system shall define processes for risk assessment, risk treatment, event detection, incident response, internal and external reporting, and management review, and shall remain proportionate to the nature and complexity of the organisation.

Aviation note.

Part-IS scope is bounded by aviation safety impact, not general IT, so the ISMS boundary must be justified against safety consequences and may sit inside the existing safety management system.

Evidence your competent authority examines
  • The documented ISMS scope statement listing activities, facilities and assets with potential aviation safety impact
  • The information security management manual or equivalent controlling document
  • Approved ISMS processes for risk, events, incidents and reporting
  • Records showing the ISMS is operational and reviewed rather than only documented
Common finding they raise: The ISMS exists on paper as policies but has no evidence of being operated, with risk assessments and incident logs never populated.

Why this is not another template pack

  • The evidence is the point. A requirement you cannot evidence is a gap. This tells you exactly what a competent authority examines and the finding they raise, for every provision.
  • Safety-impact scoped. Part-IS covers information security risks with a potential aviation-safety impact. That scoping is written into every control, not left for you to infer.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. Part-IS aligns closely with ISO 27001, so this work feeds a broader security certification if you pursue one.

Who buys this

Aviation design, production, operator, maintenance, CAMO and training organisations coming into Part-IS scope, the safety and security managers who own it, and aviation compliance consultants. Whether it is your first Part-IS implementation or a gap closure, you save weeks and walk in with the ISMS and evidence ready.

By the end of the weekend you will have
✓  An adopt-ready control for all 32 requirements
✓  A completed Part-IS control matrix
✓  The evidence a competent authority examines
✓  Your ISMS integrated with your management system
✓  A readiness percentage and a fix list
✓  The reporting obligations built in

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does this make me Part-IS approved? Approval is granted by your competent authority. The Kit gets you ready: the ISMS, the risk work, and the exact evidence an authority examines, for every requirement.

Does it cover reporting? Yes. Mandatory reporting to the competent authority is a requirement group of its own, because it is a frequent gap.

Does it integrate with my SMS? Yes. Part-IS must sit inside your existing management system, and the controls are written to do exactly that.

What if it is not for me? A 30-day money-back guarantee.

Do not decode two EU regulations from scratch.
The Part-IS requirement set is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be authority-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com