Online course

EASA Part-IS Information Security Awareness Training for Aviation Organisations

Fully Compliant with Annex II (Part-IS.I.OR) of Implementing Regulation (EU) 2023/203

Welcome to your essential online training portal for Part-IS Information Security Awareness.

In an era of hyper-connected cockpits, digital maintenance logs, electronic flight bags, and network-linked ground support, aviation safety is no longer just a physical concern. Cyber threats, ransomware, corrupted software loads, and unauthorised system access can compromise airworthiness just as severely as a structural failure.

This interactive e-learning course is specifically designed to fulfil the Information Security Awareness mandate set out in Annex II (Part-IS.I.OR) of EASA Implementing Regulation (EU) 2023/203. It embeds an "Information Security for Safety" mindset into your workforce's daily routines.

Aligning Security with Safety Management

Regulation (EU) 2023/203 requires aviation organisations to implement an Information Security Management System (ISMS) integrated seamlessly with their existing Safety Management Systems (SMS).

This awareness course bridges the gap between traditional IT security and operational aviation safety, showing every employee how their actions protect the entire airworthiness value chain.

Key Topics Covered

Structured precisely around Part-IS.I.OR organisational requirements, the curriculum delivers straightforward, high-impact instruction:

  • Understanding Part-IS: Why EASA introduced Regulation (EU) 2023/203 and how information security directly affects flight safety.
  • The ISMS Framework: Roles, responsibilities, and how your organisation's ISMS interfaces with Part-145, Part-CAMO, and Part-ORO workflows.
  • Threat Identification & Risk Awareness: Recognising common cyber vectors targeting aviation, including phishing, rogue USB devices, compromised software updates, and social engineering.
  • Asset & System Protection: Best practices for securing safety-critical data, digital technical logs, diagnostic software, and avionics ground equipment.
  • Internal & External Incident Reporting: How to identify an information security event, follow the internal reporting scheme, and support authority reporting obligations.

The Part-IS Core Rule: Information security in aviation isn't about protecting corporate spreadsheets - it’s strictly concerned with preventing cyber events from compromising aircraft safety, maintenance integrity, or operational decisions.

Who Needs This Training?

This awareness course is mandatory for all personnel working within EASA-approved organisations governed by Part-IS.I.OR, including:

  • Part-145 Maintenance Personnel (Certifying staff, engineers, and workshop technicians accessing digital manuals or diagnostic tools).
  • CAMO Personnel (Airworthiness planners, records staff, and system administrators).
  • Flight & Ground Operations Personnel relying on electronic systems and operational databases.
  • Quality, Safety, Compliance, and Nominated Postholder Teams responsible for organisational security culture, ISMS oversight, and audit readiness.

Fast, Flexible & Audit-Ready

  • EASA Compliant: Aligned with the latest Part-IS AMC/GM guidelines to guarantee audit success.
  • Self-Paced Learning: Accessible 24/7 on desktop, tablet, or mobile devices.
  • Instant Certification: Automated end-of-course evaluation with downloadable certificates for your compliance records.

Ensure your organisation is fully compliant to the new Part-IS regulation. Enrol Now or Contact Us for Corporate Integrations.