Online Course: Information Security Risk Assessment in Civil Aviation
💡 This course is part of the Academy of Information Security in Civil Aviation - PART-IS Manager training. |
Description and Objectives of the Training
The course covers all steps of the information security risk assessment in accordance with the requirements of Part-IS.I.OR.205 and the international standards ISO 31000:2018, ISO/IEC 27001:2022, and ISO/IEC 27005:2022. Through seven thematic blocks, participants become familiar with the key concepts, principles, and methods for assessing and treating risks. Special emphasis is placed on establishing context, identifying threats and vulnerabilities, performing both quantitative and qualitative assessments, deciding on risk acceptability, and planning effective risk treatment measures. The theoretical content is reinforced by practical exercises that link acquired knowledge with real-life situations in the aviation environment. The programme concludes with an integrated practical exercise and a final knowledge assessment.
Target Audience
This course is intended for individuals involved in the assessment, treatment, and oversight of information security risks within aviation sector organizations. It also applies to those participating in the implementation of ISMS requirements in line with Part-IS.I.OR.205 and associated standards. The course is suitable for personnel already working in aviation organizations (AOC, CAMO, aerodromes, service providers, IT support, security managers, etc.).
Course Content
➤ Introduction to Risk Assessment Participants are introduced to the fundamentals of the risk concept in the context of information security, the role of risk management within the ISMS framework, and the applicable regulatory requirements and standards. The importance of IS.I.OR.205 is explained as a core requirement of the Part-IS framework, along with its correlation to the ISO 31000, ISO 27001, and ISO 27005 standards. This introduction provides essential understanding of the purpose of risk assessment and its place within the information security management system of an aviation organization. ➤ Scope, Context and Criteria Participants learn the steps for defining the scope of the risk assessment and establishing the context in line with ISO guidelines. The topic covers the development of both internal and external context, including stakeholder identification and the definition of risk assessment criteria – such as levels of likelihood and impact, as well as the boundaries of risk acceptability. The organisation must first clearly understand its own context, including assets, processes, and relationships with external parties, and based on that, define criteria that enable a structured and consistent approach to information security risk assessment. ➤ Risk Identification This topic addresses the process of identifying information assets, threats, vulnerabilities, and potential incidents that could affect the safety of aviation operations. Participants learn how to collect information using available documentation, interviews with key personnel, workshops, and the use of checklists. Special emphasis is placed on understanding the interconnection between assets and external relationships that may increase exposure to risk. The concept of risk scenarios is also introduced, helping to visualise possible consequences of events based on real operational contexts. The content is aligned with the identification requirements of Part-IS.I.OR and the principles of international standards that define a systematic approach to identifying risks within an organisation’s information system. Exercise 2: Identification of Assets, Threats and Vulnerabilities |
Certificate of Competence
All participants who successfully complete the practical exercises and pass the final exam will be issued a certificate of competence for conducting information security risk assessment in civil aviation, in accordance with the Information Security and Oversight Requirements of the European Union Aviation Safety Agency (PART-IS.I.OR).
Learning Outcomes
Upon completion of the training, participants will be able to:
- Understand the purpose and structure of risk assessment within the requirements of Part-IS.I.OR.
- Be able to define the scope, context, and criteria for risk assessment.
- Know how to identify information assets, threats, and vulnerabilities.
- Independently analyse and evaluate risks using appropriate methods.
- Be capable of developing strategies and risk treatment plans in line with standard requirements.
- Link risk assessment with other ISMS processes and documentation.
- Prepare key elements of documentation subject to oversight.
- Apply knowledge to practical examples from the aviation domain.
Literature
|
Discounts
We offer attractive discounts for group registrations. The applicable rates are as follows:
|
Additional information: Bojan Varga, e-mail: bojan.varga@siq.si
-
Dates: 21.07.2025-22.07.2025ID: 18739Please choose a dateRegistration
-
Duration:
2 Days (09:00 - 16:00)
16 school hours - Lecturer: Davorin Kacian
- Registration fee: 916,00 EUR (does not include VAT)
We value and reward your loyalty
That is why we are introducing the Loyalty Bonus to reward our loyal participants.
More about loyalty bonus