EASA PART-IS · EXTERNAL IT

What role does an external IT provider play in Part-IS?

Outsourcing IT does not outsource accountability. External services need clear scope, risk treatment, access control and technical evidence.

riatech GmbHIT · Software · Technology
Many aviation organizations rely on external partners for infrastructure, Microsoft 365, security, backup and support. Those interfaces need to be controllable and documented within the organization’s information security framework.
01

Define technical responsibilities clearly

Unclear ownership creates gaps: who patches, monitors, reacts to alerts or disables privileged access?

  • define covered systems and services
  • assign technical responsibilities
  • define escalation paths
  • plan technical cover and emergency access
02

Treat external access as a critical asset

Remote support and provider admin access are part of the security architecture.

  • personalized admin accounts
  • MFA and Conditional Access
  • limited access paths
  • logging and privileged access review
03

Provide technical evidence for implemented controls

Customers need more than “configured securely”. Relevant technical controls should be demonstrable.

  • asset and system information
  • MFA and Conditional Access evidence
  • backup and restore documentation
  • network, monitoring and patch information
04

Be technically available during audits

Technical questions can be resolved faster when the service provider can explain architecture and translate findings into measures.

  • answer technical questions
  • explain evidence
  • prioritize findings
  • update implementation and evidence