Becoming Part-IS compliant follows a fairly logical path, even if the detail differs from one organisation to the next. Most begin with a gap analysis to see how their current setup measures against the regulation. From there, the typical steps are:

  • Define the scope and decide who is accountable for information security.
  • Carry out an information security risk assessment, with a clear focus on risks that could affect aviation safety.
  • Document everything in an Information Security Management Manual, often shortened to ISMM.
  • Put detection, reporting and incident response processes in place.
  • Train your staff so everyone involved understands their responsibilities.
  • Review and audit the system so you can show it works in practice.

Because Part-IS is an ongoing system rather than a one off task, many organisations bring in specialist support. Aero Compliance Solutions works with aviation operators through each of these stages, from the first gap analysis to a working ISMS.