<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Margaux LEFEUBVRE, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/margaux-lefeubvre/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 16 Jan 2025 08:20:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Margaux LEFEUBVRE, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>PART-IS: A pillar of cybersecurity in European aviation</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/01/part-is-a-pillar-of-cybersecurity-in-european-aviation/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/01/part-is-a-pillar-of-cybersecurity-in-european-aviation/#respond</comments>
		
		<dc:creator><![CDATA[Margaux LEFEUBVRE]]></dc:creator>
		<pubDate>Thu, 16 Jan 2025 08:20:54 +0000</pubDate>
				<category><![CDATA[Focus]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=25140</guid>

					<description><![CDATA[<p>In a world where aviation safety is increasingly based on digital systems, the PART-IS regulation introduced by the European Union Aviation Safety Agency (EASA) marks a decisive turning point.     This innovation is due to increasing numbers of cybersecurity standards, regulations,...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/01/part-is-a-pillar-of-cybersecurity-in-european-aviation/">PART-IS: A pillar of cybersecurity in European aviation</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><b><span data-contrast="auto">In a world where aviation safety is increasingly based on digital systems, the PART-IS regulation introduced by the European Union Aviation Safety Agency (EASA) marks a decisive turning point.</span></b><span data-contrast="auto">   </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">This innovation is due to increasing numbers of cybersecurity standards, regulations, and directives- such as NIS2 (Network and Information Systems Security Directive), the Cyber Resilience Act (CRA), and sector-specific regulations. This expanding regulatory framework reflects the need to secure critical infrastructures and technological products in the face of growing threats. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">This article explores the PART-IS regulation, its implication, scope, stakeholders involved, essential requirements, and steps involved in complying with it. </span><span data-ccp-props="{}"> </span></p>
<h1>What is PART-IS? Why is it essential?  </h1>
<p><span data-contrast="auto">PART-IS was introduced to enhance aviation security by</span><b><span data-contrast="auto"> protecting critical information systems in aviation</span></b><span data-contrast="auto">. Its main objective is to ensure that these systems, which include technologies such as avionics communications and air traffic management, are resilient in the face of cyber threats to guarantee the continuity and safety of aviation operations in a sector where any failure can have serious consequences. With the growing integration of digital technologies into aviation operations, from navigation systems to ground infrastructure, the sector&#8217;s vulnerability to cyber-attacks has increased considerably. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">By requiring aviation industry players to identify and assess the vulnerabilities of their systems, PART-IS is a </span><b><span data-contrast="auto">proactive response</span></b><span data-contrast="auto"> to today&#8217;s challenges. </span><span data-ccp-props="{}"> </span></p>
<h1>Which systems are concerned?  </h1>
<p><span data-contrast="auto">PART-IS applies to all digital systems used in civil aviation. This includes, for example:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li><span data-contrast="auto">On-board systems, such as Flight Management Systems (FMS) </span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Air Traffic Management (ATM) infrastructures </span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Predictive maintenance systems </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">Due to the increasing interconnectivity between these systems, a vulnerability in one component can cause a chain reaction across the entire aviation ecosystem; jeopardising the safety of operations. </span><span data-ccp-props="{}"> </span></p>
<h1>Who are the stakeholders?  </h1>
<p><span data-contrast="auto">The implementation of the PART-IS is based on collaboration between several stakeholders. The main players involved include:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Airline operators</span></b><span data-contrast="auto">, who are responsible for the safety of on-board systems </span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Manufacturers</span></b><span data-contrast="auto">, who must incorporate cybersecurity measures into the design of aircraft and equipment </span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Air navigation service providers</span></b><span data-contrast="auto">, responsible for protecting traffic management systems </span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">National authorities</span></b><span data-contrast="auto">, whose role is to supervise and verify regulatory compliance </span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Ground service providers  </span></b><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{}"> <img fetchpriority="high" decoding="async" class="size-full wp-image-25133 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_01.png" alt="" width="1456" height="526" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_01.png 1456w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_01-437x158.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_01-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_01-768x277.png 768w" sizes="(max-width: 1456px) 100vw, 1456px" /></span></p>
<p><span data-contrast="auto">Part-IS will be mandatory from October 2025 for organisations approved by EASA under Delegated Regulation (EU) 2022/1645, i.e. production and design organisations. Maintenance organisations under Delegated Regulation (EU) 2023/203 will have to comply by February 2026. </span><span data-ccp-props="{}"> </span></p>
<p><img decoding="async" class="size-full wp-image-25131 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_02.png" alt="" width="1412" height="246" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_02.png 1412w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_02-437x76.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_02-71x12.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_02-768x134.png 768w" sizes="(max-width: 1412px) 100vw, 1412px" /></p>
<h1>What are the PART-IS requirements?  </h1>
<p><span data-contrast="auto">The PART-IS regulation imposes fundamental principles for guaranteeing the security of critical systems. The organisations concerned must adopt a rigorous approach to meet these requirements and ensure their compliance. </span><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"><img decoding="async" class="size-full wp-image-25129 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_03.png" alt="" width="1448" height="864" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_03.png 1448w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_03-320x191.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_03-65x39.png 65w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/part_IS_03-768x458.png 768w" sizes="(max-width: 1448px) 100vw, 1448px" /></span></p>
<h2>Risk management (ISMS)  </h2>
<p><span data-contrast="auto">This regulation is part of a proactive approach aimed at identifying, analysing, and mitigating the risks that could compromise the confidentiality, integrity, and availability of sensitive information. Based on a structured framework such as ISO/IEC 27001, the ISMS becomes a central tool for establishing robust security policies, deploying appropriate technical and organisational measures, and raising stakeholders&#8217; awareness of cybersecurity issues. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Risk management, a fundamental pillar of this approach, enables efforts to be prioritised on the basis of identified vulnerabilities, while ensuring continuous improvement through the PDCA (Plan-Do-Check-Act) cycle. Regulations require civil aviation operators and entities to have robust information security governance in line with best practice.  </span><span data-ccp-props="{}"> </span></p>
<h2>Risk assessment  </h2>
<p><span data-contrast="auto">Organisations must establish a structured methodology for identifying, analysing, and mitigating the cyber risks associated with their information systems. This includes carrying out vulnerability analyses, assessing the impact in the event of a compromise, and implementing appropriate controls. </span><span data-ccp-props="{}"> </span></p>
<h2>Continuous monitoring </h2>
<p><span data-contrast="auto">Real-time monitoring of systems is essential for detecting and responding rapidly to security incidents. This requires the use of advanced tools and the implementation of incident response protocols. All incidents must be reported quickly and accompanied by a clear response plan to limit their impact. </span><span data-ccp-props="{}"> </span></p>
<h2>Training and awareness  </h2>
<p><span data-contrast="auto">Staff must be trained in cyber security best practice to reduce the risk of human error. Regular awareness programmes are essential to maintain a high level of vigilance. </span><span data-ccp-props="{}"> </span></p>
<h2>Audits and documentation  </h2>
<p><span data-contrast="auto">Compliance with PART-IS is verified through regular audits conducted by EASA or national authorities. Organisations must also maintain full documentation covering safety policies, procedures implemented, and incidents encountered. </span><span data-ccp-props="{}"> </span></p>
<h1>What are the key stages in achieving compliance?   </h1>
<p><span data-contrast="auto">Compliance with PART-IS offers a strategic opportunity for companies to strengthen the security of their critical systems and modernise their practices. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">With the compliance deadline set for October 2025 for at least part of the perimeter, is an appropriate time to start the compliance process. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">To achieve this, we are currently supporting our customers in 3 main areas:  </span><span data-ccp-props="{}"> </span></p>
<ul>
<li><span data-contrast="auto">Firstly, it is essential to </span><b><span data-contrast="auto">precisely define the scope concerned</span></b><span data-contrast="auto">, based on the scope of the approvals issued by the EASA, in order to effectively frame the efforts.  </span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Next, </span><b><span data-contrast="auto">drawing up an Information Security Management System</span></b><span data-contrast="auto"> (ISMS) will help structure the policies and processes required for proactive risk management.  </span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Finally, </span><b><span data-contrast="auto">carrying out the first risk analyses</span></b><span data-contrast="auto"> to identify vulnerabilities and draw up appropriate action plans.  </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto">These steps lay the foundations for a solid, long-term information security strategy, which will then have to be nurtured and developed in the spirit of the continuous improvement process advocated by PART-IS.</span><span data-ccp-props="{}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/01/part-is-a-pillar-of-cybersecurity-in-european-aviation/">PART-IS: A pillar of cybersecurity in European aviation</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/01/part-is-a-pillar-of-cybersecurity-in-european-aviation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
