Product Security (Cyber Security) is focussed on the individual project development and addressed by regulation such as AMC 20-42 from EASA.
Information Security (IS) addresses information security, including non-IT based security, at the organisational level. And is mandated by regulation such as EU regulation 2022/1645 (for design and production organisations and others) or 2023/203 (for maintenance organisations and others). The requirements defined in these regulations are commonly referred to as Part-IS.
The scope is on the organisation itself and the handling of information security, supporting guidance is given by several accepted industry standards:
- ED-201A/DO-391 for organisational aspects of the stakeholders involved (authorities, design organisations, suppliers),
- Standards also referenced in Product Cyber Security (ED-202B, ED-203A, ED-204A, ED-206) for risk assessments, continued airworthiness aspects and event reporting.
Setting up the required Information Security Management Systems (ISMS) for your organisation can be a daunting task. Especially with Information Security, tailored solutions, that consider your company’s size, setup and history, are important. Otherwise, either inadequate means are implemented, or overburdened solutions are selected, which add a lot of unnecessary effort. TSSC can support you with expertise in this endeavour, addressing the various aspects of Part-IS.
Defining the ISMS as part of your Design Organisation (DO) Handbook (DOH) is one task, where we can support you.
However, apart from the DOH, which is limited to show compliance to Part-IS, one also needs to define company Policies, Guidelines and Instructions to support the implementation of Part-IS in your organisation. TSSC can support you by defining these tailored to your organisational situation and parameters.
Training
For training information see Training