Online Course: Information Security Incident Management in Civil Aviation
💡 This course is part of the Academy of Information Security in Civil Aviation - PART-IS Manager training. |
Description and Objectives of the Training
The course consists of seven thematically connected modules that guide participants through the key phases of effective information security incident management in the aviation sector. The program begins with an introduction to essential concepts, regulatory requirements, and standards, followed by planning and preparation of the incident management system, detection and reporting of information security events and incidents, assessment, and decision-making on further actions. It continues with the execution of response activities and analysis of lessons learned, and concludes with a comprehensive practical workshop in which participants apply their acquired knowledge in a simulated environment. The course is based on the requirements of Part-IS.I.OR and aligned with the standards ISO/IEC 27001:2022, ISO/IEC 27035-1:2023, and ISO/IEC 27031:2025. Special value is added through structured exercises that support the development of practical competencies essential for effective incident management in the aviation environment.
Target Audience
This course is intended for professionals involved in the management of information security and operational safety in the aviation sector. It is particularly beneficial for individuals responsible for security processes, members of incident response teams, IT administrators, ISMS managers, CAMO representatives, aviation operators, providers of aviation infrastructure services, and other personnel whose activities may affect aviation safety through the use of information systems.
Course Content
➤ Introduction to Incident Management Effective management of information security incidents is essential for maintaining the safety and reliability of aviation systems. Given the sector’s high dependency on digital infrastructure, any incident can seriously threaten aviation safety, system availability, data protection, and operational readiness. Part-IS.I.OR defines the obligations of organizations to establish an incident management system that includes detection, reporting, assessment, response, and recovery. This module introduces the fundamental concepts needed to understand how information security incidents are managed within an Information Security Management System (ISMS). Key terms such as event, incident, vulnerability, and threat indicator are explained, along with their relevance in the aviation security context. ➤ Planning and Preparation Planning and preparation form the foundation for building an effective incident management system. According to Part-IS.I.OR, organizations must develop an incident detection and response policy and plan, define roles and responsibilities (IMT, IRT), establish communication channels, set rules for involving external stakeholders, and define training requirements for personnel. In this phase, the organization should also determine its priorities and measurable recovery objectives, including MBCO (Minimum Business Continuity Objective), RTO (Recovery Time Objective), and RPO (Recovery Point Objective), as outlined in ISO/IEC 27031:2025. All elements of the plan must be aligned with the existing ISMS and supported by appropriate resources and procedures. Exercise 1: Development of an Incident Management Policy and Plan ➤ Detection and Reporting Early detection and proper reporting of information security events are essential for timely response and maintaining operational safety. Part-IS.I.OR requires organizations to establish both internal and external reporting systems, including the obligation to report events that could impact aviation safety. The reporting mechanism must be reliable, accessible, and well-known to all employees, and must also allow submissions from contracted third parties. Reported events must be appropriately analysed and forwarded to designated contacts within the organization to enable timely initiation of further actions. ➤ Assessment and Decision-Making ➤ Incident Response The response phase involves the operational management of the incident with the goal of minimizing further damage, stabilizing systems, and regaining control. Part-IS.I.OR outlines the implementation of both technical and organizational measures, along with clearly defined communication procedures involving all relevant stakeholders. A key role is played by the recovery team, which is responsible for restoring system functionality as quickly as possible. Their task is to ensure that essential operations continue with minimal disruption and that recovery is achieved within the planned timeframe. The effectiveness of this phase significantly impacts the organization’s overall resilience and its readiness to handle future incidents. ➤ Lessons Learned Exercise 5: Preparing the Incident Report ➤ Practical Incident Management Workshop ➤ Final Exam |
Certificate of Competence
All participants who successfully complete the practical exercises and pass the final examination will be awarded a certificate of competence in managing information security incidents in civil aviation, in accordance with the Information Security and Oversight Requirements of the European Union Aviation Safety Agency (PART-IS.I.OR).
Learning Outcomes
Upon completion of the training, participants will be able to:
- explain the importance of incident management in the context of aviation safety,
- identify events that may escalate into information security incidents,
- correctly complete reporting forms for events and incidents,
- make decisions on response activation based on defined criteria,
- develop a technical and communication response plan for incidents,
- evaluate the effectiveness of implemented measures and propose corrective actions,
- collaborate effectively within a team during a simulated security incident.
Literature
|
Discounts
We offer attractive discounts for group registrations. The applicable rates are as follows:
|
Additional information: Bojan Varga, e-mail: bojan.varga@siq.si
-
Dates: 05.08.2025-06.08.2025ID: 18741Please choose a dateRegistration
-
Duration:
2 Days (09:00 - 16:00)
16 school hours - Lecturer: Davorin Kacian
- Registration fee: 916,00 EUR (does not include VAT)
We value and reward your loyalty
That is why we are introducing the Loyalty Bonus to reward our loyal participants.
More about loyalty bonus