This is one of the most common questions, and the short answer is no, not on its own. ISO 27001 is a strong starting point because much of it aligns with what Part-IS expects from an ISMS. The key difference is focus. ISO 27001 is built around protecting information in general, while Part-IS is built around aviation safety, which means you have to show how an information security risk could affect the safe operation of aircraft.

If you already hold ISO 27001, you can take credit for a lot of the groundwork, but you still need to fold aviation safety into your risk management and meet the specific Part-IS requirements that ISO 27001 does not cover. EASA has published mapping guidance to help organisations bridge the gap between the two.