Part-IS Awareness

New

Contact Training Department

Diana Lünse
Diana LünseHead of Training

This foundational session is designed specifically for management teams across operational, technical, and support domains within aviation organisations subject to Part-IS.I.OR. The workshop supports the development of a shared understanding of the regulatory expectations and the broader aviation information security landscape, in line with the requirements of Part-IS.I.OR.240(a)(3), GM1 Part-IS.I.OR.200, and EASA Executive Director Decision 2025/011/R.

Unlike a traditional lecture, this is not a chapter-by-chapter walkthrough of the regulation. Nor does it require any prior knowledge of IT or cybersecurity. Instead, it provides a strategic and accessible overview of the key concepts, risks, governance arrangements, and organisational responsibilities associated with information security in aviation.

The workshop explores how information security contributes to operational resilience, safety assurance, business continuity, and regulatory compliance. Particular attention is given to the role of management in establishing the necessary leadership, governance, resources, and organisational culture required to support an effective Information Security Management System (ISMS).

Through interactive discussions, real-world aviation scenarios, and practical examples, participants will gain an understanding of how information security decisions influence operational performance and organisational objectives. The course focuses on management awareness and oversight responsibilities rather than technical implementation activities.

Tailored for organisations subject to Part-IS.I.OR, including Aircraft Operators, Continuing Airworthiness Management Organisations (CAMOs), Part-145 Maintenance Organisations, and Approved Training Organisations (ATOs), the workshop provides managers and decision-makers with the knowledge necessary to understand their responsibilities, support organisational compliance, and promote a positive information security culture throughout the organisation.

This training course is conducted in cooperation with nerd.aero.

Course Details

Location:In-house
Language:English
Duration:1 days
Provider:airsight GmbH

Course Content

Introduction to EASA Part-IS

  • Regulatory framework and applicability
  • Organisational responsibilities and accountability
  • Information security, safety and compliance
  • Regulatory oversight expectations

Interactive Introduction to Information Security

  • Core information security concepts
  • Threats and vulnerabilities
  • Human and organisational factors
  • Aviation-specific challenges

ISMS Fundamentals

  • Purpose and principles of an Information Security Management System
  • Governance and organisational responsibilities
  • Risk-based management approach
  • Monitoring and continual improvement

Risk Treatment

  • Principles of information security risk management
  • Risk treatment strategies
  • Management decision-making
  • Oversight of residual risks

The ISMS Team

  • Governance and organisational arrangements
  • Roles and responsibilities
  • Leadership, competence and awareness
  • Coordination with Safety and Compliance functions

Detect, Respond, Recover

  • Incident and event management principles
  • Response and escalation arrangements
  • Recovery and organisational resilience
  • Business continuity considerations

Reporting and Improvement

  • Reporting and monitoring activities
  • Management review and oversight
  • Corrective actions and lessons learned
  • Continual improvement of the ISMS

Recap and Final Q&A

  • Key takeaways
  • Common implementation challenges
  • Management priorities for successful compliance
  • Questions and discussion

 

Trainer

Rachel Shuter

This training course is conducted in cooperation with nerd.aero and will be delivered by their trainer, Rachel Shuter.

Rachel is an aviation professional with 13 years’ experience across commercial airlines, business aviation and aviation software. She now specialises in EASA Part-IS.

Combining operational knowledge with regulatory expertise, Rachel designs and delivers training, workshops and advisory services on Information Security Management Systems (ISMS).

She is experienced in translating regulatory requirements into practical implementation for operators and supports organisations with compliance, risk management and FCISO services.

Target Group

  • Accountable Managers
  • Nominated Persons and their Deputies
  • Senior and Middle Management involved in the relevant processes
  • Quality Assurance and Audit Personnel
  • Competent Authority Personnel
  • Inspectors and Auditors

Organisational Details

airsight offers this training course on request, worldwide. At the end of the course, all participants will receive an airsight certificate based on EASA training regulations, which is highly recognised throughout the aviation industry.

About airsight Training

airsight Training course quality

airsight operates an ISO 9001 certified Quality Management System and pursues the objective to provide high quality services that fully meet the clients’ needs.

Show more