Information security as a new key regulatory issue
With Part-IS (Information Security), the European Union Aviation Safety Agency is expanding its regulatory framework to include binding specifications on information security. The aim is to systematically protect civil aviation against cyber threats, data manipulation, IT failures and unauthorised access.
The increasing digitalisation of operational processes - from electronic flight preparation tools and digital maintenance documentation to networked flight operation systems - also makes smaller organisations potential targets for attack. At the same time, many processes are now dependent on a stable IT infrastructure. A successful cyberattack can therefore not only cause economic damage, but also have a direct impact on flight safety.
Part-IS therefore establishes binding requirements for:
- Risk assessment and protection needs analysis
- Organisational responsibilities for information security
- Reporting processes for security incidents
- Training and sensitisation
- Documentation and continuous monitoring
The requirements apply not only to major airlines, but also to other airlines:
- Flight schools (ATO/DTO)
- Commercial CAT flight operations
- NCC operator (Non-Commercial Complex)
- Maintenance organisations according to Part-145
- CAMO organisations
It is precisely here that a tension arises between regulatory requirements and practical feasibility.
Small businesses under considerable pressure to implement
While larger organisations often already have compliance and IT security departments, many smaller aviation companies work with very lean structures. One person often takes on several functions - from safety manager to administrative manager.
The introduction of a comprehensive information security management system can quickly seem disproportionate in such structures. Documentation obligations, risk analyses, training certificates and reporting processes generate administrative costs that can hardly be covered in terms of personnel and finances.
Against this backdrop, industry representatives are lobbying the European Union Aviation Safety Agency and the Federal Ministry for Digital and Transport for practicable and proportionate solutions. The aim is to ensure that small companies can achieve a high level of protection without being forced to implement oversized management systems that are disproportionate to the size of the company.
Sample instructions as a pragmatic interim solution
In order to provide concrete support to affected companies, a sample guide has been developed that translates the key requirements of Part-IS into a lean, practical structure.
The approach behind it is clear:
- Concentration on material risks
- Simple, comprehensible documentation
- Clear responsibilities
- Realistic action plans
The sample documents enable small companies to submit an application on time and thus formally fulfil regulatory requirements. Even if such a sample application cannot, of course, cover every individual case completely, it provides a reliable basis for dialogue with the competent authority.
Compliance with the deadlines is essential. After the application has been submitted, the authority can provide targeted feedback and request adjustments. This iterative approach is also in line with official practice when introducing new regulations.
Implementation by the authorities still under development
Another aspect that is causing discussion in the industry is the implementation status on the part of the authorities. According to current information, the national authorities are still in the process of fully establishing the internal structures required as part of the Part-IS Authority Requirements.
This means that the supervisory authority is also in a transition phase. Against this background, it is expected that a sense of proportion will be exercised in the case of slightly delayed or incomplete applications - especially if it is recognisable that a company is seriously addressing the issue.
Cyber risks in general aviation are increasing
The introduction of Part-IS is no coincidence. The number of reported cyber incidents in critical infrastructures is continuously increasing worldwide. Aviation is not immune to this.
Typical areas of risk in general aviation include
- Ransomware attacks on maintenance companies
- Manipulation or failure of flight planning software
- Compromised e-mail systems
- Inadequately secured cloud services
- Lack of access controls to digital documentation
Smaller organisations in particular are often considered „easy targets“ as they invest less in IT security. Part-IS aims to establish minimum standards that apply uniformly across Europe.
Conclusion: Balance between safety and proportionality
With Part-IS, information security will finally become an integral part of safety management in aviation. For small flight schools, CAT and NCC operators and maintenance companies, this means a considerable need for organisational adaptation.
It will be crucial to find the right balance: On the one hand, cyber risks must be taken seriously and addressed systematically. On the other hand, regulatory requirements must not structurally overburden small companies.
Pragmatic model solutions, a constructive dialogue with the authorities and a proportionate application of the requirements can help to ensure that information security in general aviation does not become an administrative burden, but a genuine safety gain.
Source references:
AOPA
