Regulations and Government
EASA Part-IS Regulations To Bolster Data Security
Safety-focused European Information Security Management Systems requirement comes fully into effect later this month
EASA headquarters in Cologne, Germany
The EU Aviation Safety Agency will acquire EASA-approved organizations to comply with the new digital resilience measures.

The second wave of a new mandatory European aviation regulatory framework for information security management systems (ISMS) comes into effect on Sunday. An extension of existing safety regulations, EASA Part-IS (information security) will establish additional requirements for managing information security risks, focusing on safeguarding operations and strengthening resilience in civil aviation.

Although similar to existing protocols, Part-IS requirements also include a risk-based approach to protect digital assets and operations that—if compromised—could negatively impact aviation safety.