Part-IS Implementierung
Übersetzung folgt
Our Part-IS Implementation Workshops provide practical, hands-on guidance for aviation professionals seeking to comply with EASA's Part-IS regulations. Designed for individuals with a basic understanding of the regulations, the workshops focus on actionable strategies for implementation and the practical application of information security management principles.
Aligned with the requirements of Commission Implementing Regulation (EU) 2023/203, together with the associated Acceptable Means of Compliance (AMC) and Guidance Material (GM), the course provides practical guidance on establishing, implementing, maintaining, and continuously improving an Information Security Management System (ISMS) within aviation organisations.
The sessions simplify complex information security concepts, making them accessible to non-IT personnel while maintaining a strong focus on practical implementation. Through real-world examples, interactive exercises, case studies, and facilitated discussions, participants gain hands-on experience in identifying information assets, assessing threats and vulnerabilities, performing risk assessments, defining treatment plans, and implementing effective governance and incident management processes.
Special attention is given to the practical implementation of the requirements contained within Part-IS.I.OR.200 to Part-IS.I.OR.240, enabling participants to translate regulatory obligations into effective organisational processes and documented evidence of compliance. The workshop also provides guidance on developing the key elements of an ISMS, including policies, procedures, risk registers, reporting mechanisms, and the Information Security Management Manual (ISMM).
Participants also receive valuable resources and guidance materials to support the development of their Information Security Management System (ISMS). Tailored for organisations subject to Part-IS.I.OR, including Aircraft Operators, Continuing Airworthiness Management Organisations (CAMOs), Part-145 Maintenance Organisations, and Approved Training Organisations (ATOs), the workshop equips professionals with the practical tools, implementation techniques, and regulatory understanding required to achieve and maintain effective compliance with EASA Part-IS requirements.
In contrast to the Management Training course, this workshop is specifically intended for personnel directly involved in implementation activities, including Information Security Managers, Compliance Monitoring Managers, Safety Managers, Quality Managers, Operational Managers, nominated persons, and other staff responsible for the implementation, maintenance, or oversight of Part-IS compliance programmes.
This training course is conducted in cooperation with nerd.aero.
Kursinfo
Ort:BerlinSprache:Englisch
Datum:24.11. - 25.11.2026
Dauer:2 Tage
Anbieter:airsight GmbH
Kursgebühr
Für Kurse in Berlin:
Allen Kunden werden 19% Mehrwertsteuer berechnet. Für mehr Informationen besuchen Sie bitte die englischsprachige About Taxes Seite.
Der Endpreis wird auf Ihrer Rechnung ausgewiesen.
Hinweis: Wenn Sie mehrere Teilnehmer anmelden wollen, aber einzelne Rechnungen für jeden benötigen, melden Sie bitte jeden Teilnehmer separat an.
Die Online-Anmeldung richtet sich an Unternehmen, Behörden und Organisationen. Wenn Sie als Privatperson teilnehmen möchten, kontaktieren Sie uns bitte unter training@airsight.de.
Inhalt
*Übersetzung folgt*
First Day
Introduction to EASA Part-IS
- Regulatory framework and objectives
- Scope and applicability of Part-IS
- Organisational responsibilities and accountability
- Regulatory oversight expectations
ISMS Fundamentals
- Principles of an Information Security Management System
- Governance and accountability
- Risk-based approach
- Integration within organisational processes
Interactive Introduction to Information Security Fundamentals
- Key information security concepts
- Threats, vulnerabilities and human factors
- Information security within aviation operations
- Security culture and awareness
Aviation Safety Implications of Information Security
- Information security and aviation safety
- Safety-related systems and information
- Operational impacts of security events
- Organisational resilience considerations
Finding Assets and Vulnerabilities
- Identification of information assets
- Asset ownership and responsibilities
- Vulnerability identification
- Asset inventory principles
Practical Exercise
- Identify information assets
- Identify associated vulnerabilities
Threats, Scenarios, Risk Assessment
- Threat sources and threat scenarios
- Principles of risk assessment
- Likelihood and impact evaluation
- Risk prioritisation
Practical Exercise
- Identify potential threats
- Assess likelihood and impact
- Evaluate and prioritise risks
Second Day
Recap of Day 1
- Review of key concepts
- Lessons learned and discussion
Risk Treatment
- Risk treatment strategies
- Selection of security measures
- Risk treatment planning
- Residual risk management
Detect, Respond, Recover
- Information security incident management
- Escalation and response activities
- Recovery and organisational resilience
Reporting and Improvement
- Reporting and monitoring activities
- Corrective actions and lessons learned
- Continual improvement
The Part-IS Team
- Roles and responsibilities
- Governance arrangements
- Cross-functional collaboration
- Competence and awareness
ISMM, Policies, Procedures
- Information Security Management Manual (ISMM)
- Policies and supporting procedures
- Risk and incident documentation
- Demonstrating compliance
Recap of Part-IS Training
- Key implementation principles
- Common implementation challenges
- Compliance success factors
- Final discussion and Q&A
Referenten
Rachel Shuter
Diese Schulung wird in Zusammenarbeit mit nerd.aero durchgeführt und von der Trainerin Rachel Shuter geleitet.
Rachel ist Luftfahrtexpertin mit 13 Jahren Erfahrung in den Bereichen Verkehrsfluggesellschaften, Business Aviation und Luftfahrtsoftware. Sie ist auf EASA Part-IS spezialisiert.
Sie verbindet operatives Luftfahrtwissen mit regulatorischer Expertise und konzipiert sowie leitet Schulungen, Workshops und Beratungsleistungen zu Informationssicherheitsmanagementsystemen (ISMS).
Sie verfügt über Erfahrung darin, regulatorische Anforderungen in die praktische Umsetzung für Betreiber zu übertragen, und unterstützt Organisationen bei Compliance, Risikomanagement und FCISO-Services.
Zielgruppe
- Personal, das unmittelbar an der Umsetzung beteiligt ist, einschließlich:
- Informationssicherheitsmanager (Information Security Managers)
- Compliance Monitoring Manager
- Safety Manager
- Qualitätsmanager
- Operative Führungskräfte / Betriebsverantwortliche
- sowie sonstiges Personal, das für die Implementierung, Aufrechterhaltung oder Überwachung von Programmen zur Einhaltung der Anforderungen von Part-IS verantwortlich ist.
Veranstaltungsort
Wir bitten die Teilnehmer, ihre Reise- und Hotelbuchungen selbst vorzunehmen. Für eine Unterbringung empfehlen wir unser Tagungshotel. Weitere Hinweise dazu finden Sie in Ihrer Anmeldebestätigung. Wir möchten darauf hinweisen, dass ab Januar 2025 in Berlin eine Übernachtungssteuer (City Tax) von 7,5% auf beruflich und geschäftlich veranlasste Übernachtungen erhoben wird.
Die Kursgebühr umfasst die Teilnahme am Lehrgang, das Kursmaterial sowie für nicht-virtuelle Kurse die Verpflegung während des Lehrgangs (Kaffeepausen und Business Lunch).
Organisatorische Details
Die Tagungszeiten sind wie folgt gestaffelt:
erster Lehrgangstag: 10.00 - 17.00 Uhr
letzter Lehrgangstag: 8.00 - 16.00 Uhr
Die Verpflegung während des Lehrgangs (Kaffeepausen und Business Lunch) ist in der Kursgebühr enthalten. Nach erfolgreicher Kursteilnahme erhalten alle Teilnehmer ein airsight-Zertifikat nach EASA-Trainingsregularien, welches weltweit in der Luftfahrtbranche anerkannt ist.
Über unsere Lehrgänge
Zertifizierte Qualität
airsight verfügt über ein nach ISO 9001 zertifiziertes Qualitätsmanagementsystem, in dessen Mittelpunkt die Maximierung des Kundennutzens steht. Wir arbeiten ständig an Verbesserungen – so auch bei unseren Lehrgängen, die wir auch anhand des Teilnehmerfeedbacks kontinuierlich optimieren.
Kursinfo
Ort:In-houseSprache:Englisch
Dauer:2 Tage
Anbieter:airsight GmbH
Inhalt
*Übersetzung folgt*
First Day
Introduction to EASA Part-IS
- Regulatory framework and objectives
- Scope and applicability of Part-IS
- Organisational responsibilities and accountability
- Regulatory oversight expectations
ISMS Fundamentals
- Principles of an Information Security Management System
- Governance and accountability
- Risk-based approach
- Integration within organisational processes
Interactive Introduction to Information Security Fundamentals
- Key information security concepts
- Threats, vulnerabilities and human factors
- Information security within aviation operations
- Security culture and awareness
Aviation Safety Implications of Information Security
- Information security and aviation safety
- Safety-related systems and information
- Operational impacts of security events
- Organisational resilience considerations
Finding Assets and Vulnerabilities
- Identification of information assets
- Asset ownership and responsibilities
- Vulnerability identification
- Asset inventory principles
Practical Exercise
- Identify information assets
- Identify associated vulnerabilities
Threats, Scenarios, Risk Assessment
- Threat sources and threat scenarios
- Principles of risk assessment
- Likelihood and impact evaluation
- Risk prioritisation
Practical Exercise
- Identify potential threats
- Assess likelihood and impact
- Evaluate and prioritise risks
Second Day
Recap of Day 1
- Review of key concepts
- Lessons learned and discussion
Risk Treatment
- Risk treatment strategies
- Selection of security measures
- Risk treatment planning
- Residual risk management
Detect, Respond, Recover
- Information security incident management
- Escalation and response activities
- Recovery and organisational resilience
Reporting and Improvement
- Reporting and monitoring activities
- Corrective actions and lessons learned
- Continual improvement
The Part-IS Team
- Roles and responsibilities
- Governance arrangements
- Cross-functional collaboration
- Competence and awareness
ISMM, Policies, Procedures
- Information Security Management Manual (ISMM)
- Policies and supporting procedures
- Risk and incident documentation
- Demonstrating compliance
Recap of Part-IS Training
- Key implementation principles
- Common implementation challenges
- Compliance success factors
- Final discussion and Q&A
Referenten
Rachel Shuter
Diese Schulung wird in Zusammenarbeit mit nerd.aero durchgeführt und von der Trainerin Rachel Shuter geleitet.
Rachel ist Luftfahrtexpertin mit 13 Jahren Erfahrung in den Bereichen Verkehrsfluggesellschaften, Business Aviation und Luftfahrtsoftware. Sie ist auf EASA Part-IS spezialisiert.
Sie verbindet operatives Luftfahrtwissen mit regulatorischer Expertise und konzipiert sowie leitet Schulungen, Workshops und Beratungsleistungen zu Informationssicherheitsmanagementsystemen (ISMS).
Sie verfügt über Erfahrung darin, regulatorische Anforderungen in die praktische Umsetzung für Betreiber zu übertragen, und unterstützt Organisationen bei Compliance, Risikomanagement und FCISO-Services.
Zielgruppe
- Personal, das unmittelbar an der Umsetzung beteiligt ist, einschließlich:
- Informationssicherheitsmanager (Information Security Managers)
- Compliance Monitoring Manager
- Safety Manager
- Qualitätsmanager
- Operative Führungskräfte / Betriebsverantwortliche
- sowie sonstiges Personal, das für die Implementierung, Aufrechterhaltung oder Überwachung von Programmen zur Einhaltung der Anforderungen von Part-IS verantwortlich ist.
Organisatorische Details
airsight bietet diesen Lehrgang auf Anfrage als In-House-Schulung an.
Nach erfolgreicher Kursteilnahme erhalten alle Teilnehmer ein airsight-Zertifikat nach EASA-Trainingsregularien, welches weltweit in der Luftfahrtbranche anerkannt ist.
Über unsere Lehrgänge
Zertifizierte Qualität
airsight verfügt über ein nach ISO 9001 zertifiziertes Qualitätsmanagementsystem, in dessen Mittelpunkt die Maximierung des Kundennutzens steht. Wir arbeiten ständig an Verbesserungen – so auch bei unseren Lehrgängen, die wir auch anhand des Teilnehmerfeedbacks kontinuierlich optimieren.


Sie wollen 5+ Teilnehmer anmelden? Fragen Sie nach einem In-House-Kurs an Ihrem Standort oder online!


