Becoming Part-IS compliant follows a fairly logical path, even if the detail differs from one organisation to the next. Most begin with a gap analysis to see how their current setup measures against the regulation. From there, the typical steps are:
- Define the scope and decide who is accountable for information security.
- Carry out an information security risk assessment, with a clear focus on risks that could affect aviation safety.
- Document everything in an Information Security Management Manual, often shortened to ISMM.
- Put detection, reporting and incident response processes in place.
- Train your staff so everyone involved understands their responsibilities.
- Review and audit the system so you can show it works in practice.
Because Part-IS is an ongoing system rather than a one off task, many organisations bring in specialist support. Aero Compliance Solutions works with aviation operators through each of these stages, from the first gap analysis to a working ISMS.

