# Part-IS Familiarization and Cybersecurity Essentials

> Part-IS familiarisation and cybersecurity awareness for aviation staff, referenced to Regulations (EU) 2022/1645 and 2023/203.

- Course code: PART-IS
- Price: 65.00 EUR per seat
- Classroom equivalent: 8 hours
- Pass mark: 75%
- HTML syllabus: https://mxcourse.net/courses/PART-IS

Part-IS familiarization and cybersecurity awareness for aviation personnel. Sixteen modules combine safety-linked explanations, worked examples, supplier and risk decisions, reporting timelines and recovery scenarios with 48 interactive mid-course questions, specific feedback, free retries and takeaway recaps. No written assignments or uploads. The 8-hour classroom-equivalent learning plan is an instructional estimate for guided study, scenario analysis, discussion and review; it is not measured online attendance, an enforced timer or an authority-prescribed minimum. Actual self-paced completion time varies. After all sections, the separate final examination draws 12 questions; 75% (nine correct) is required. Three failed attempts require section review under the platform rules. A course-completion certificate supports awareness evidence, not specialist competence, regulatory approval or workplace authorization.

This online aviation training course is designed for controlled seat assignment, recorded trainee progress, final assessment, and certificate issue after passing.

Course revision 3, reviewed 2026-09-10. References support the training scope; operational use requires current applicable rules and the organisation’s accepted procedures.

## Syllabus

16 modules, completed in order.

1. Welcome & course scope
  - Keywords: scope, audience, assessment, practical exercise, Build your learning record
  - Objective: Orient to the Part-IS course scope and assessment. Apply this through three interactive scenario decisions with feedback and retries.
2. Why Part-IS exists — the safety connection
  - Keywords: information security, safety connection, rationale, practical exercise, Trace the route from information to safety
  - Objective: Explain why Part-IS exists and its connection to aviation safety. Apply this through three interactive scenario decisions with feedback and retries.
3. Two regulations, one framework
  - Keywords: 2022/1645, 2023/203, scope, applicability, practical exercise, An applicability decision is an evidence trail
  - Objective: Distinguish the two Part-IS regulations and their scope. Apply this through three interactive scenario decisions with feedback and retries.
4. The vocabulary — definitions and the chain
  - Keywords: definitions, information security event, incident, chain, practical exercise, Classify observations without inventing certainty
  - Objective: Define the Part-IS vocabulary and the event-to-incident chain. Apply this through three interactive scenario decisions with feedback and retries.
5. The four pillars — C·I·A·A
  - Keywords: confidentiality, integrity, availability, authenticity, practical exercise, Protect a record throughout its life
  - Objective: Explain the C·I·A·A pillars of information security. Apply this through three interactive scenario decisions with feedback and retries.
6. The ISMS and the rule map — IS.I.OR.100 to 260
  - Keywords: ISMS, IS.I.OR, rule map, requirements, practical exercise, Turn the rule map into an operating system
  - Objective: Navigate the ISMS rule map from IS.I.OR.100 to 260. Apply this through three interactive scenario decisions with feedback and retries.
7. Risk assessment and treatment — IS.I.OR.205 and 210
  - Keywords: risk assessment, treatment, IS.I.OR.205, IS.I.OR.210, practical exercise, Workshop: build and challenge a risk register
  - Objective: Apply information-security risk assessment and treatment. Apply this through three interactive scenario decisions with feedback and retries.
8. Detection, response and recovery — IS.I.OR.220
  - Keywords: detection, response, recovery, IS.I.OR.220, practical exercise, Recovery means restoring trust as well as service
  - Objective: Describe the detection, response and recovery requirements. Apply this through three interactive scenario decisions with feedback and retries.
9. Reporting — the internal scheme and the external clock
  - Keywords: internal reporting, external reporting, deadlines, scheme, practical exercise, Workshop: write a report while facts are incomplete
  - Objective: Apply the internal reporting scheme and external reporting timelines. Apply this through three interactive scenario decisions with feedback and retries.
10. People, contracting, records and improvement
  - Keywords: personnel, contracting, records, continuous improvement, practical exercise, Workshop: supplier access, evidence and management action
  - Objective: Explain the people, contracting, records and improvement duties. Apply this through three interactive scenario decisions with feedback and retries.
11. Who is the threat?
  - Keywords: threat actors, insiders, motivation, capability, practical exercise, Threat actors: assess access and motive separately
  - Objective: Identify who the information-security threats are. Apply this through three interactive scenario decisions with feedback and retries.
12. How organisations get hacked — the six doors
  - Keywords: attack vectors, phishing, credentials, the six doors, practical exercise, Workshop: challenge a request before trusting it
  - Objective: Recognise the common ways organisations are compromised. Apply this through three interactive scenario decisions with feedback and retries.
13. The attacks by name — and aviation's real incidents
  - Keywords: ransomware, phishing, supply chain, aviation incidents, practical exercise, Learn from incidents without copying unsupported conclusions
  - Objective: Name the major attack types and learn from real aviation incidents. Apply this through three interactive scenario decisions with feedback and retries.
14. Could this be you? Three Monday-morning scenarios
  - Keywords: scenarios, awareness, application, decisions, practical exercise, Capstone: a maintenance-record incident across organisations
  - Objective: Apply security awareness to realistic workplace scenarios. Apply this through three interactive scenario decisions with feedback and retries.
15. On the shop floor — what you actually do differently
  - Keywords: habits, passwords, USB, reporting, shop floor, practical exercise, Make the good practice usable on your next shift
  - Objective: Adopt the personal security habits the rule requires on the shop floor. Apply this through three interactive scenario decisions with feedback and retries.
16. Course summary & personal checklist
  - Keywords: summary, personal checklist, self-check, practical exercise, Consolidate your evidence and prepare for assessment
  - Objective: Consolidate learning with a personal information-security checklist. Apply this through three interactive scenario decisions with feedback and retries.

## Final assessment

- Format: 12 multiple-choice questions drawn from the course question bank, with the options shuffled each attempt.
- Pass mark: 75%.
- Certificate: issued automatically on passing, according to Regulations (EU) 2022/1645 and (EU) 2023/203 — EASA Easy Access Rules for Information Security (December 2025 revision).

## Classroom training equivalent

Approximately 8 hours of classroom-equivalent study, case analysis and review. This is an instructional planning estimate, not measured online attendance or a regulatory minimum.

## Related training topics

- [Part-IS information security training](https://mxcourse.net/training/part-is-information-security-training.md)
## Guides

- [A map of EASA continuing-airworthiness training](https://mxcourse.net/guides/easa-continuing-airworthiness-training-map.md)
## Common questions

### Is this a hacker or IT-admin course?

No. It is aviation staff awareness: recognise safety-linked information-security risk, report, and think through recovery.

### How long is this course?

The published classroom-equivalent estimate is 8 hours. Self-paced completion time varies. The figure is a planning estimate, not measured attendance.

### Do I get a certificate?

Yes. After every module is complete, a 12-question examination must be passed at 75%. A named certificate is then issued automatically and can be checked on the public certificate checker.
