top of page

Responding to Information Security Vulnerabilities Under EASA Part-IS (IS.I.OR.220)

  • Writer: Luka Pace Bonello
    Luka Pace Bonello
  • Jun 14
  • 5 min read

In the previous article, Responding to Information Security Incidents Under EASA Part-IS (IS.I.OR.220), we looked at what response means when a confirmed incident is on your hands: prioritise by safety impact, engage the right people, and contain the threat before it spreads further.


Vulnerability response is different. There is no active breach. No data has been confirmed as corrupted, no system demonstrably compromised. But a weakness exists, one that could be exploited, and IS.I.OR.220 requires that it be managed.


If you're implementing Part-IS and unsure you're on the right track - that's a common challenge. I've helped aviation organisations build compliant ISMSs that are audit-ready, aligned with safety, and work in practice.


👉 Reach out if you'd like to take a clear, structured approach to Part-IS, or subscribe to the Aviation Cybersecurity Brief for practical insights + my Free Part-IS Starter Checklist (covering what most organisations miss early on).


Aircraft mechanic in blue coveralls checks a tablet in an aircraft hangar, with a jet, tool cart, and another worker in the background.

The Nature of Vulnerability Response


A vulnerability is a flaw or weakness in a system, process, or design that has not yet been exploited, but could be. The absence of active harm does not mean the absence of risk. In an aviation context, a vulnerability affecting systems that support safety-critical operations represents a potential pathway to an incident — and, depending on the system, potentially an unsafe condition.


That absence of urgency is precisely where vulnerability response can go wrong. Organisations that treat an unexamined weakness as a low-priority matter are making a risk decision without having done the analysis to support it. Vulnerability response exists to ensure that decision is deliberate, not accidental.


A CAMO Scenario


Consider a Continuing Airworthiness Management Organisation. Within its ISMS scope sits an airworthiness management platform — the system used to track aircraft maintenance status, monitor component life limits, and manage airworthiness directives. If its data is corrupted or manipulated, aircraft could remain in service beyond safe limits, or maintenance actions could be missed entirely. The downstream safety consequences are clear.


Then a vendor advisory arrives, disclosing a vulnerability in the database engine underpinning the platform — a flaw that could allow an authenticated user to modify records without the change being captured in the audit log. No evidence suggests exploitation. But the weakness is confirmed applicable to the platform version the CAMO operates.


This is the starting point for vulnerability response and management.


Assessing the Vulnerability


The first step is not to patch, mitigate, or escalate. It is to understand the vulnerability in the context of the specific environment and organisation.


A vulnerability scoring system — such as the Common Vulnerability Scoring System (CVSS) — provides a useful starting point. It offers a structured way to assess characteristics such as how exploitable the weakness is, what level of access is required to trigger it, and what the potential impact on confidentiality, integrity, and availability might be. In the CAMO scenario, the integrity dimension is the critical one: the ability to modify airworthiness records without an audit trail directly threatens the safety function of the system.


Scoring provides a baseline. But the score alone does not tell the full story. A vulnerability rated moderate in a generic context may be high priority in a safety-critical aviation environment — and a technically severe vulnerability may be effectively constrained by existing controls that limit realistic exploitation in the organisational context.


This is why scoring leads into a risk assessment, not a response decision. The assessment examines the vulnerability in context: who could realistically exploit it, and with what consequence for aviation safety. Under Part-IS, considering the worst-case exploitation scenario within the risk assessment is mandated.


From Assessment to Decision


The risk assessment produces an informed picture of the actual risk. From that picture, a decision is made.


If the assessed risk is acceptable, because existing controls limit the realistic pathway to exploitation, or the potential impact does not threaten the organisation’s acceptable level of safety, the vulnerability may be managed through continued monitoring. That is a legitimate risk-based decision, provided it is documented and reviewed.


If the assessed risk is unacceptable, because the pathway to exploitation is realistic, and the potential consequence crosses the threshold of an unsafe condition, treatment is required. That treatment, prioritised in accordance with criticality, might take the form of a patch, a configuration change, an access restriction, or a combination of all. The form is less important than the outcome: reducing the risk to a level the organisation has assessed as acceptable, with the safety implications clearly understood.


Critically, this decision must involve the right people. Where a vulnerability could affect aviation safety, safety teams must form part of the assessment — ensuring the safety perspective is present when the risk is weighed, not added retrospectively.


Key Principles


  • Score first, decide second: Vulnerability scoring provides a structured baseline for prioritisation and communication. The score informs the assessment — it does not replace it.

  • Context changes the risk picture: A vulnerability’s severity in the abstract may not reflect its actual risk in a specific environment. The assessment must consider the organisation’s specific systems, controls, and safety dependencies.

  • Unacceptable risks require treatment: Where the assessed risk crosses the threshold of an unsafe condition, treatment is mandatory under IS.I.OR.205 — not discretionary.

  • Safety must be present in the decision: Where a vulnerability could affect safety-relevant systems, safety teams must be involved in the assessment and the treatment decision.

  • Decisions must be documented: Whether the outcome is treatment or monitored acceptance, the reasoning must be recorded. An undocumented risk decision is not a risk decision — it is an oversight.


What Vulnerability Response Looks Like in Practice


The practical discipline of vulnerability response is not about speed. It is about structure: a consistent process for receiving and reviewing disclosures, scoring and assessing vulnerabilities in a way that is repeatable and auditable, and tracking treatment decisions through to completion.


The safety manager’s involvement is essential. It is the mechanism that connects vulnerability response to the safety management system — ensuring the organisation’s risk tolerance for information security events is calibrated against, not separate from, its operational safety standards.


A Quick Summary


Vulnerability response under IS.I.OR.220 is a structured, risk-led process. It begins with scoring and contextual assessment, moves to a safety-informed decision, and ends with a documented outcome — whether treatment or monitored acceptance.


An unassessed vulnerability is a risk decision made by default. IS.I.OR.220 requires that the decision is made deliberately, with the safety implications understood and the outcome recorded.


For organisations managing incidents in parallel, the next stage is recovery — restoring systems to a safe and secure state. That is addressed in a subsequent article.


Navigating Part-IS? Let's Make It Work.


Achieving Part-IS compliance goes far beyond ticking boxes. It's about building something that actually works - under audit, under pressure, and alongside your existing SMS.


I've led aviation organisations through their Part-IS journey, achieving successful compliance with ISMS implementations that are practical, audit-ready, and aligned with safety.


If you're currently navigating Part-IS, or unsure whether your approach will stand up to oversight, it's worth having a conversation.


👉 Reach out if you'd like to discuss how to approach Part-IS in a clear, structured way.

Comments


bottom of page