
How to Get Certified to ISO 27001?

How to Get Certified to ISO 27701?

EASA Part-IS is a regulation specifically designed to address Information Security within the Aviation industry. Its goal is to ensure that aviation organizations implement effective security controls as part of an Information Security Management System (ISMS) to protect data and assets that may impact safety in aviation operations. The regulation provides a systematic approach to securing critical information and systems.
The regulation applies to organizations involved in aviation-related activities, particularly those that manage information systems and data critical to aviation safety. This includes organizations such as: Aircraft Operators; Maintenance; Air Traffic Management; and other aviation service providers that provide critical data and information systems.
The regulation closely aligns with other international security standards such as ISO 27001 and directs organisations to establish a formal ISMS as well as regular risk management practices.
Core security controls include:
Additionally, continued compliance with aviation safety regulations such as EASA Part-145 and Part-66 is required along with Incident Reporting and Monitoring, Training and Awareness and Continuous Improvement.
EASA Part-IS does not require a formal external certification audit to be completed. However, achieving and maintaining compliance through a defined methodological approach will ensure your organization is compliant and can demonstrate pro activeness to compliance which is expected by regulatory bodies. Having a valid ISO 27001 certificate will go a long way to helping meet the requirements of EASA Part-IS as the regulation is strongly aligned with ISO 27001 requirements.
Dionach have been partnering with clients for over 25 years to help them achieve Information Security compliance across a wide range of security certifications and regulations including one of our core focus areas, ISO 27001. Some key steps we can work with you on include:
We will review your current security compliance position looking at any current security certifications you may have already and articulate what additional controls are required to meet Part-IS requirements.
A full gap assessment against the Part-IS regulation. We will conduct walkthrough meetings with your teams to understand what security controls you have in place and document your current compliance position highlighting where you meet requirements and where gaps exist.
Once we have established your compliance position, we will articulate a roadmap that will detail the next steps you need to take to achieve full compliance, and the timelines and costs associated.
While on your journey towards compliance we can assist you with the formalization of security controls and provide technical solutions via our parent company, Nomios, to help you achieve compliance.
Head: Joanne Morley (GRC Client Relationship Manager)
Tel: +44 (0) 7710 796377
Email: [email protected]
We deliver the whole spectrum of cybersecurity services, from long-term, enterprise wide strategy and implementation projects to single penetration tests.
Our team works with you to identify and assess your organization’s vulnerabilities, define enterprise-wide goals, and advise how best to achieve them.
Our recommendations are clear, concise, pragmatic and tailored to your organization.
Independent, unbiased, personalized – this is how we define our services. We guide you to spend wisely and invest in change efficiently.