Part-IS Implementation
Our Part-IS Implementation Workshops provide practical, hands-on guidance for aviation professionals seeking to comply with EASA's Part-IS regulations. Designed for individuals with a basic understanding of the regulations, the workshops focus on actionable strategies for implementation and the practical application of information security management principles.
Aligned with the requirements of Commission Implementing Regulation (EU) 2023/203, together with the associated Acceptable Means of Compliance (AMC) and Guidance Material (GM), the course provides practical guidance on establishing, implementing, maintaining, and continuously improving an Information Security Management System (ISMS) within aviation organisations.
The sessions simplify complex information security concepts, making them accessible to non-IT personnel while maintaining a strong focus on practical implementation. Through real-world examples, interactive exercises, case studies, and facilitated discussions, participants gain hands-on experience in identifying information assets, assessing threats and vulnerabilities, performing risk assessments, defining treatment plans, and implementing effective governance and incident management processes.
Special attention is given to the practical implementation of the requirements contained within Part-IS.I.OR.200 to Part-IS.I.OR.240, enabling participants to translate regulatory obligations into effective organisational processes and documented evidence of compliance. The workshop also provides guidance on developing the key elements of an ISMS, including policies, procedures, risk registers, reporting mechanisms, and the Information Security Management Manual (ISMM).
Participants also receive valuable resources and guidance materials to support the development of their Information Security Management System (ISMS). Tailored for organisations subject to Part-IS.I.OR, including Aircraft Operators, Continuing Airworthiness Management Organisations (CAMOs), Part-145 Maintenance Organisations, and Approved Training Organisations (ATOs), the workshop equips professionals with the practical tools, implementation techniques, and regulatory understanding required to achieve and maintain effective compliance with EASA Part-IS requirements.
In contrast to the Management Training course, this workshop is specifically intended for personnel directly involved in implementation activities, including Information Security Managers, Compliance Monitoring Managers, Safety Managers, Quality Managers, Operational Managers, nominated persons, and other staff responsible for the implementation, maintenance, or oversight of Part-IS compliance programmes.
This training course is conducted in cooperation with nerd.aero.
Course Details
Location:BerlinLanguage:English
Date:24.11. - 25.11.2026
Duration:2 days
Provider:airsight GmbH
Course Fee
For courses in Berlin:
All customers will be charged 19% VAT. For more information please see our About Taxes page.
The final price will be shown on your invoice.
Please note: If you want to register several particpants from your company but need a single invoice for each, please register each of them seperately.
Online registration is intended for companies, public authorities and other organisations. If you would like to attend as a private individual, please contact us at training@airsight.de.
Course Content
First Day
Introduction to EASA Part-IS
- Regulatory framework and objectives
- Scope and applicability of Part-IS
- Organisational responsibilities and accountability
- Regulatory oversight expectations
ISMS Fundamentals
- Principles of an Information Security Management System
- Governance and accountability
- Risk-based approach
- Integration within organisational processes
Interactive Introduction to Information Security Fundamentals
- Key information security concepts
- Threats, vulnerabilities and human factors
- Information security within aviation operations
- Security culture and awareness
Aviation Safety Implications of Information Security
- Information security and aviation safety
- Safety-related systems and information
- Operational impacts of security events
- Organisational resilience considerations
Finding Assets and Vulnerabilities
- Identification of information assets
- Asset ownership and responsibilities
- Vulnerability identification
- Asset inventory principles
Practical Exercise
- Identify information assets
- Identify associated vulnerabilities
Threats, Scenarios, Risk Assessment
- Threat sources and threat scenarios
- Principles of risk assessment
- Likelihood and impact evaluation
- Risk prioritisation
Practical Exercise
- Identify potential threats
- Assess likelihood and impact
- Evaluate and prioritise risks
Second Day
Recap of Day 1
- Review of key concepts
- Lessons learned and discussion
Risk Treatment
- Risk treatment strategies
- Selection of security measures
- Risk treatment planning
- Residual risk management
Detect, Respond, Recover
- Information security incident management
- Escalation and response activities
- Recovery and organisational resilience
Reporting and Improvement
- Reporting and monitoring activities
- Corrective actions and lessons learned
- Continual improvement
The Part-IS Team
- Roles and responsibilities
- Governance arrangements
- Cross-functional collaboration
- Competence and awareness
ISMM, Policies, Procedures
- Information Security Management Manual (ISMM)
- Policies and supporting procedures
- Risk and incident documentation
- Demonstrating compliance
Recap of Part-IS Training
- Key implementation principles
- Common implementation challenges
- Compliance success factors
- Final discussion and Q&A
Trainer
Rachel Shuter
This training course is conducted in cooperation with nerd.aero and will be delivered by their trainer, Rachel Shuter.
Rachel is an aviation professional with 13 years’ experience across commercial airlines, business aviation and aviation software. She now specialises in EASA Part-IS.
Combining operational knowledge with regulatory expertise, Rachel designs and delivers training, workshops and advisory services on Information Security Management Systems (ISMS).
She is experienced in translating regulatory requirements into practical implementation for operators and supports organisations with compliance, risk management and FCISO services.
Target Group
- personnel directly involved in implementation activities, including:
- Information Security Managers,
- Compliance Monitoring Managers,
- Safety Managers,
- Quality Managers,
- Operational Managers,
- and other staff responsible for the implementation, maintenance, or oversight of Part-IS compliance programmes.
Course Location
Participants are responsible for making their own travel arrangements. The accommodation and travel costs are at the charge of the participants. Please note that airsight does not perform any travel and hotel bookings for the participants. Rooms can however be booked directly by the participants by contacting the hotel. We would like to point out that from January 2025 a City Tax of 7.5% will be imposed on overnight stays for business and professional purposes in Berlin.
The course fee includes the registration, training material and examination. For non-virtual courses, coffee breaks and business lunch are also included.
Organisational Details
The course hours are scheduled as follows:
first training day: 10:00 am - 5:00 pm
last training day: 8:00 am - 4:00 pm
Coffee breaks and business lunch are included in the course fee. At the end of the course, all participants will receive an airsight certificate based on EASA training regulations, which is highly recognised throughout the aviation industry.
About airsight Training
airsight Training course quality
airsight operates an ISO 9001 certified Quality Management System and pursues the objective to provide high quality services that fully meet the clients’ needs.
Course Details
Location:In-houseLanguage:English
Duration:2 days
Provider:airsight GmbH
Course Content
First Day
Introduction to EASA Part-IS
- Regulatory framework and objectives
- Scope and applicability of Part-IS
- Organisational responsibilities and accountability
- Regulatory oversight expectations
ISMS Fundamentals
- Principles of an Information Security Management System
- Governance and accountability
- Risk-based approach
- Integration within organisational processes
Interactive Introduction to Information Security Fundamentals
- Key information security concepts
- Threats, vulnerabilities and human factors
- Information security within aviation operations
- Security culture and awareness
Aviation Safety Implications of Information Security
- Information security and aviation safety
- Safety-related systems and information
- Operational impacts of security events
- Organisational resilience considerations
Finding Assets and Vulnerabilities
- Identification of information assets
- Asset ownership and responsibilities
- Vulnerability identification
- Asset inventory principles
Practical Exercise
- Identify information assets
- Identify associated vulnerabilities
Threats, Scenarios, Risk Assessment
- Threat sources and threat scenarios
- Principles of risk assessment
- Likelihood and impact evaluation
- Risk prioritisation
Practical Exercise
- Identify potential threats
- Assess likelihood and impact
- Evaluate and prioritise risks
Second Day
Recap of Day 1
- Review of key concepts
- Lessons learned and discussion
Risk Treatment
- Risk treatment strategies
- Selection of security measures
- Risk treatment planning
- Residual risk management
Detect, Respond, Recover
- Information security incident management
- Escalation and response activities
- Recovery and organisational resilience
Reporting and Improvement
- Reporting and monitoring activities
- Corrective actions and lessons learned
- Continual improvement
The Part-IS Team
- Roles and responsibilities
- Governance arrangements
- Cross-functional collaboration
- Competence and awareness
ISMM, Policies, Procedures
- Information Security Management Manual (ISMM)
- Policies and supporting procedures
- Risk and incident documentation
- Demonstrating compliance
Recap of Part-IS Training
- Key implementation principles
- Common implementation challenges
- Compliance success factors
- Final discussion and Q&A
Trainer
Rachel Shuter
This training course is conducted in cooperation with nerd.aero and will be delivered by their trainer, Rachel Shuter.
Rachel is an aviation professional with 13 years’ experience across commercial airlines, business aviation and aviation software. She now specialises in EASA Part-IS.
Combining operational knowledge with regulatory expertise, Rachel designs and delivers training, workshops and advisory services on Information Security Management Systems (ISMS).
She is experienced in translating regulatory requirements into practical implementation for operators and supports organisations with compliance, risk management and FCISO services.
Target Group
- personnel directly involved in implementation activities, including:
- Information Security Managers,
- Compliance Monitoring Managers,
- Safety Managers,
- Quality Managers,
- Operational Managers,
- and other staff responsible for the implementation, maintenance, or oversight of Part-IS compliance programmes.
Organisational Details
airsight offers this training course on request, worldwide. At the end of the course, all participants will receive an airsight certificate based on EASA training regulations, which is highly recognised throughout the aviation industry.
About airsight Training
airsight Training course quality
airsight operates an ISO 9001 certified Quality Management System and pursues the objective to provide high quality services that fully meet the clients’ needs.


Training 5 or more people? Ask for an In-house course at your premises or online!


