PART-IS · Course syllabus
Part-IS Familiarization and Cybersecurity Essentials
Overview
Part-IS familiarization and cybersecurity awareness for aviation personnel. Sixteen modules combine safety-linked explanations, worked examples, supplier and risk decisions, reporting timelines and recovery scenarios with 48 interactive mid-course questions, specific feedback, free retries and takeaway recaps. No written assignments or uploads. The 8-hour classroom-equivalent learning plan is an instructional estimate for guided study, scenario analysis, discussion and review; it is not measured online attendance, an enforced timer or an authority-prescribed minimum. Actual self-paced completion time varies. After all sections, the separate final examination draws 12 questions; 75% (nine correct) is required. Three failed attempts require section review under the platform rules. A course-completion certificate supports awareness evidence, not specialist competence, regulatory approval or workplace authorization.
This online aviation training course is designed for controlled seat assignment, recorded trainee progress, final assessment, and certificate issue after passing.
Course revision 3, reviewed 2026-09-10. References support the training scope; operational use requires current applicable rules and the organisation’s accepted procedures.
Target groups
Auditors, Compliance Monitoring Managers, Safety Investigators, Safety personnel, Safety Managers, CAMO staff, CAMO Post Holder, Maintenance staff, Certifying Staff, Mechanics, Pilots, Managers
Syllabus
16 modules, completed in order — each with its keywords and objective.
-
1
Welcome & course scope
scopeaudienceassessmentpractical exerciseBuild your learning recordObjective: Orient to the Part-IS course scope and assessment. Apply this through three interactive scenario decisions with feedback and retries.
-
2
Why Part-IS exists — the safety connection
information securitysafety connectionrationalepractical exerciseTrace the route from information to safetyObjective: Explain why Part-IS exists and its connection to aviation safety. Apply this through three interactive scenario decisions with feedback and retries.
-
3
Two regulations, one framework
2022/16452023/203scopeapplicabilitypractical exerciseAn applicability decision is an evidence trailObjective: Distinguish the two Part-IS regulations and their scope. Apply this through three interactive scenario decisions with feedback and retries.
-
4
The vocabulary — definitions and the chain
definitionsinformation security eventincidentchainpractical exerciseClassify observations without inventing certaintyObjective: Define the Part-IS vocabulary and the event-to-incident chain. Apply this through three interactive scenario decisions with feedback and retries.
-
5
The four pillars — C·I·A·A
confidentialityintegrityavailabilityauthenticitypractical exerciseProtect a record throughout its lifeObjective: Explain the C·I·A·A pillars of information security. Apply this through three interactive scenario decisions with feedback and retries.
-
6
The ISMS and the rule map — IS.I.OR.100 to 260
ISMSIS.I.ORrule maprequirementspractical exerciseTurn the rule map into an operating systemObjective: Navigate the ISMS rule map from IS.I.OR.100 to 260. Apply this through three interactive scenario decisions with feedback and retries.
-
7
Risk assessment and treatment — IS.I.OR.205 and 210
risk assessmenttreatmentIS.I.OR.205IS.I.OR.210practical exerciseWorkshop: build and challenge a risk registerObjective: Apply information-security risk assessment and treatment. Apply this through three interactive scenario decisions with feedback and retries.
-
8
Detection, response and recovery — IS.I.OR.220
detectionresponserecoveryIS.I.OR.220practical exerciseRecovery means restoring trust as well as serviceObjective: Describe the detection, response and recovery requirements. Apply this through three interactive scenario decisions with feedback and retries.
-
9
Reporting — the internal scheme and the external clock
internal reportingexternal reportingdeadlinesschemepractical exerciseWorkshop: write a report while facts are incompleteObjective: Apply the internal reporting scheme and external reporting timelines. Apply this through three interactive scenario decisions with feedback and retries.
-
10
People, contracting, records and improvement
personnelcontractingrecordscontinuous improvementpractical exerciseWorkshop: supplier accessevidence and management actionObjective: Explain the people, contracting, records and improvement duties. Apply this through three interactive scenario decisions with feedback and retries.
-
11
Who is the threat?
threat actorsinsidersmotivationcapabilitypractical exerciseThreat actors: assess access and motive separatelyObjective: Identify who the information-security threats are. Apply this through three interactive scenario decisions with feedback and retries.
-
12
How organisations get hacked — the six doors
attack vectorsphishingcredentialsthe six doorspractical exerciseWorkshop: challenge a request before trusting itObjective: Recognise the common ways organisations are compromised. Apply this through three interactive scenario decisions with feedback and retries.
-
13
The attacks by name — and aviation's real incidents
ransomwarephishingsupply chainaviation incidentspractical exerciseLearn from incidents without copying unsupported conclusionsObjective: Name the major attack types and learn from real aviation incidents. Apply this through three interactive scenario decisions with feedback and retries.
-
14
Could this be you? Three Monday-morning scenarios
scenariosawarenessapplicationdecisionspractical exerciseCapstone: a maintenance-record incident across organisationsObjective: Apply security awareness to realistic workplace scenarios. Apply this through three interactive scenario decisions with feedback and retries.
-
15
On the shop floor — what you actually do differently
habitspasswordsUSBreportingshop floorpractical exerciseMake the good practice usable on your next shiftObjective: Adopt the personal security habits the rule requires on the shop floor. Apply this through three interactive scenario decisions with feedback and retries.
-
16
Course summary & personal checklist
summarypersonal checklistself-checkpractical exerciseConsolidate your evidence and prepare for assessmentObjective: Consolidate learning with a personal information-security checklist. Apply this through three interactive scenario decisions with feedback and retries.
Final assessment
- Format: 12 multiple-choice questions drawn from the course question bank, with the options shuffled each attempt.
- Pass mark: 75%.
- Certificate: issued automatically on passing, according to Regulations (EU) 2022/1645 and (EU) 2023/203 — EASA Easy Access Rules for Information Security (December 2025 revision).
Classroom training equivalent
8 hours
Approximately 8 hours of classroom-equivalent study, case analysis and review. This is an instructional planning estimate, not measured online attendance or a regulatory minimum. Individual self-paced completion time varies.
Related training topics
Guides
Common questions
Is this a hacker or IT-admin course?
No. It is aviation staff awareness: recognise safety-linked information-security risk, report, and think through recovery.
How long is this course?
The published classroom-equivalent estimate is 8 hours. Self-paced completion time varies. The figure is a planning estimate, not measured attendance.
Do I get a certificate?
Yes. After every module is complete, a 12-question examination must be passed at 75%. A named certificate is then issued automatically and can be checked on the public certificate checker.