Regulation (EU) 2023/203, Annex II (Part-IS.I.OR), Section I
IS.I.OR.205: the information security risk assessment
Point IS.I.OR.205 of Part-IS requires an organisation to identify every element and interface exposed to information security risk, to assess each risk for its potential impact on aviation safety with a predefined classification, to decide whether it is acceptable or must be treated under point IS.I.OR.210, and to review the assessment when elements, interfaces, knowledge or lessons learnt change.
The text
Verbatim, with the point markers of the source. Page furniture and footnotes are left out.
(a) The organisation shall identify all its elements which could be exposed to information security risks. That shall include:
(1) the organisation’s activities, facilities and resources, as well as the services the organisation operates, provides, receives or maintains;
(2) the equipment, systems, data and information that contribute to the functioning of the elements listed in point (1).
(b) The organisation shall identify the interfaces that it has with other organisations, and which could result in the mutual exposure to information security risks.
(c) With regard to the elements and interfaces referred to in points (a) and (b), the organisation shall identify the information security risks which may have a potential impact on aviation safety. For each identified risk, the organisation shall:
(1) assign a risk level according to a predefined classification established by the organisation;
(2) associate each risk and its level with the corresponding element or interface identified in accordance with points (a) and (b). The predefined classification referred to in point (1) shall take into account the potential of occurrence of the threat scenario and the severity of its safety consequences. Based on that classification, and taking into account whether the organisation has a structured and repeatable risk management process for operations, the organisation shall be able to establish whether the risk is acceptable or needs to be treated in accordance with point IS.I.OR.210. In order to facilitate the mutual comparability of risks assessments, the assignment of the risk level pursuant to point (1) shall take into account relevant information acquired in coordination with the organisations referred to in point (b).
(d) The organisation shall review and update the risk assessment carried out in accordance with points (a), (b) and, as applicable, points (c) or (e), in any of the following situations:
(1) there is a change in the elements subject to information security risks;
(2) there is a change in the interfaces between the organisation and other organisations, or in the risks communicated by the other organisations;
(3) there is a change in the information or knowledge used for the identification, analysis and classification of risks;
(4) there are lessons learnt from the analysis of information security incidents.
(e) By derogation from point (c), organisations required to comply with Subpart C of Annex III (Part- ATM/ANS.OR) to Regulation (EU) 2017/373 shall replace the analysis of the impact on aviation safety by an analysis of the impact on their services as per the safety support assessment required by point ATM/ANS.OR.C.005. This safety support assessment shall be made available to the air traffic service providers to whom they provide services and those air traffic service providers shall be responsible for evaluating the impact on aviation safety.
Part-IS does not require the use of any specific information security framework, such as ISO, NIST or others to develop the risk assessment or in general to implement risk management. Each framework offers different benefits and none of these frameworks is perfect for an individual organisation, and should be customised and tailored to meet the overall needs of an organisation as well as the specific need to consider aviation safety aspects. Organisations whose information security frameworks have achieved industry certifications can provide this information as supporting artefacts; however, these organisations should show the applicability of the industry certification to the scope of this Regulation (see GM1 IS.I.OR.200). General guidance on risk management, including risk assessment, can be found in ISO/IEC 27005 and ISO/IEC 31000 as well as NIST SP 800-30. Aviation organisations may also wish to consider aviation- specific guidance as defined in the risk management chapter of the latest version of EUROCAE ED- 201A and, as appropriate to the specific operating environment, in the chapters of EUROCAE ED-204A, EUROCAE ED-205A and EUROCAE ED-206 covering risk management.
When conducting an information security risk assessment, the organisation should ensure that all relevant aviation safety elements are identified and included in the ISMS scope as per IS.I.OR.200 and related AMC. A means to comply with the requirement in point IS.I.OR.205(a) is to perform a preliminary high-level risk assessment or impact assessment, carried out in accordance with a documented methodology and following precise criteria for the inclusion in and exclusion from the ISMS scope of the elements listed in IS.I.OR.205(a).
What it means in practice
Point (a) asks for an inventory: the activities, facilities, resources and services, and the equipment, systems, data and information they depend on. Point (b) adds the interfaces with other organisations through which risk is shared in both directions. The AMC accepts a preliminary high-level assessment, with a documented methodology and explicit criteria for what is inside and outside the ISMS scope, as the way to build that inventory.
Point (c) is the assessment proper. Each risk that may affect aviation safety gets a level from a classification the organisation defines in advance, combining the potential of occurrence of the threat scenario with the severity of its safety consequences, and each risk is tied to the element or interface it belongs to. The classification decides whether a risk is acceptable or has to be treated under point IS.I.OR.210, and it takes account of what the interfacing organisations have communicated, so that assessments can be compared.
Point (d) names four triggers for a review: a change in the elements, a change in the interfaces or in the risks communicated by other organisations, a change in the knowledge used for the assessment, and lessons learnt from incidents. Point (e) is a derogation for ATM/ANS providers.
The GM says no framework is prescribed. ISO/IEC 27005 and 31000, NIST SP 800-30 and the EUROCAE ED-201A, ED-204A, ED-205A and ED-206 series are named as guidance, and an industry certification counts as a supporting artefact only where its applicability to the scope of the regulation is shown.
An AI assistant that reads an organisation's manuals and design data is an element under point (a). Where it runs on a vendor's cloud it is also an interface under point (b), and the vendor's communicated risks enter the classification under point (c). Where it runs on the organisation's own hardware without an outbound connection, the interface does not exist.
Where Wingman360 Teammate uses it
The on-premise guide walks through the four deployment models as elements and interfaces under points (a) and (b), and its seven questions to a vendor are inputs to the classification under point (c). Wingman360 Teammate's own deployment options are listed in the specification of each solution page.
Sources
- Easy Access Rules for Information Security (Regulations (EU) 2023/203 and 2022/1645), August 2024 revisionEuropean Union Aviation Safety Agency. Point IS.I.OR.205, GM1 IS.I.OR.205 and AMC1 IS.I.OR.205(a) quoted from the consolidated text, pages 108 to 109; checked 2026-09-20
EU regulation text is free to reproduce. EASA AMC and GM are reproduced under EASA's terms, with the source acknowledged above. United States federal regulation text is in the public domain. The full register is at /sources.