How can we implement EASA Part-IS technically?
Together with riatech: we assess your technical baseline, prioritize relevant measures, implement them in your existing infrastructure and provide the associated technical information and evidence.
Assess
Identify and document devices, servers, cloud services, users, administrative access, networks, external providers and technical dependencies.
Secure
Implement MFA, Conditional Access, network segmentation, endpoint security, secure remote access, patch management, backup and monitoring.
Document
Document configurations, responsibilities and technical measures so they can be retained internally and provided for reviews or audits in a traceable form.
Monitor
Continuously operate and monitor relevant systems, backups, security components and technical infrastructure.
Evidence
Provide structured technical information and evidence for implemented measures – for example Conditional Access, MFA, backup, logging or network segmentation.
Support
On request, we support you technically during audits, answer technical questions and help address technical findings.
Part-IS becomes concrete in IT.
Our focus is the technical implementation within your existing IT and cloud infrastructure.
Identity & Access
MFA, roles, privileged accounts, least privilege and traceable access.
Network Segmentation
Separation of critical areas, firewalls, VPN and controlled communication paths.
Endpoint Security
Hardening, encryption, endpoint protection and device state.
Logging & Monitoring
Central logging, event detection, alerting and technical traceability.
Backup & Recovery
Defined backups, offsite concepts, restoration and documented recovery processes.
Vulnerability & Patch
Manage vulnerabilities, updates, patch cycles and technical measures in a traceable way.
Incident Response
Technical procedures for security events, account compromise and system outages.
Evidence & Documentation
Document technical measures, responsibilities and evidence in an audit-ready manner.
External IT Interface
Clear separation of responsibilities and technical interfaces between the customer and IT service provider.
No unknown device. No undocumented access.
Devices that are “quickly” connected to the network can become black boxes and potential attack paths. On request, we deliver hardware fully configured, documented and inventoried and integrate it into your infrastructure in a controlled way.
Preconfigured
Firmware, baseline hardening, network parameters and intended security configuration are agreed before commissioning.
Inventoried
Relevant devices are recorded with function, location, serial number, responsibility and technical role.
Controlled Integration
IP, VLAN, firewall and access rules are defined rather than inherited by accident.
Technically Monitored
Where appropriate, availability, condition, security-relevant events and required maintenance are continuously monitored.
Assessment → Measures → Implementation → Evidence.
riatech supports the technical alignment of your IT with the defined Part-IS scope – from assessment to documented measures and technical audit support.
Technical Assessment
Assess existing systems, access and safeguards technically and prioritize action areas.
Implementation
Implement MFA, Conditional Access, segmentation, hardening, monitoring, backup, patch and access measures.
Evidence Package
For implemented measures, we provide technical information, configuration states and traceable evidence for internal retention.
Audit Support
On request, we support technical reviews and audits, explain configurations and help address technical findings.
Do you recognize your IT in these questions?
The key questions often do not start with a regulation, but with concrete technical dependencies, access and evidence.
Do you have a complete overview of which IT systems are actually within your Part-IS scope?
Servers, cloud services, VPN, mobile devices, technical systems and external service providers often evolve over time. riatech helps identify relevant systems, dependencies, access and data flows in a structured way and document them with technical traceability.
Do you know who actually has administrative access to your systems?
In addition to internal administrators, access often exists for external IT providers, vendors, maintenance partners or former employees. We review administrative accounts, remote access, roles and permissions and support clear separation of user, service and privileged accounts.
Is MFA really active everywhere it should be?
Microsoft 365 is often protected while VPN, server management, firewalls, backup systems or maintenance access are handled differently. We therefore review the entire access chain, not just one cloud service.
Could you determine today who made a critical change yesterday?
Logs alone are not enough. What matters is whether relevant events are recorded, retained long enough and can be evaluated when needed. We support logging, monitoring and technical traceability of administrative changes.
Do your backups merely exist – or can they be demonstrably restored?
A successfully reported backup does not prove systems can be reliably restored. We review backup targets, offsite copies, access rights, recovery times and recovery tests.
What happens when a Microsoft 365 account is compromised?
Changing the password is only part of the response. Active sessions, OAuth applications, forwarding rules, devices and privileged roles may still be relevant. We support prepared technical incident response procedures.
Are office IT, technical systems and external access sufficiently separated?
Flat networks simplify operations but increase the possible impact of compromised systems. We plan and implement segmentation, VLANs, firewall rules, VPN structures and clearly defined transitions between security zones.
How quickly are critical security updates actually installed?
An update process is not automatically risk-based patch management. We support prioritization, maintenance windows, technical implementation and traceable documentation.
Do you know which external service providers have access to relevant systems?
IT security does not end at your own firewall. Software vendors, cloud services and remote support can be part of the technical risk chain. We make these interfaces visible and help restrict access in a traceable way.
What happens if your external IT service provider is unavailable tomorrow?
Are administrative access, configurations, backups, firewall rules and system dependencies documented? We place great importance on documenting technical environments so they do not depend on individuals or hidden knowledge.
Can you actually evidence technical security measures during an audit?
“It is configured” is not robust technical documentation. We help document measures with system context, responsibility, configuration, evidence and change history in a traceable way.
Do you have a technical emergency plan – or only a general security concept?
During an incident, what matters is who blocks which systems, which logs are preserved, how access is reset and how operations are restored. riatech helps prepare these technical procedures in practice.
Does our entire IT need to be rebuilt because of Part-IS?
Usually not. The practical approach is to understand the existing environment, identify relevant risks and gaps, prioritize measures and implement them selectively. This is exactly what our Technical Readiness Assessment is designed for.
What happens if our internal IT owner is unavailable?
Critical IT knowledge should not depend on one person. riatech can serve as a technical fallback layer with documented infrastructure, controlled administrative access, current system knowledge and defined substitution processes.
Do you have a second administrator who could really take over in an emergency?
A second name on a contact list is not enough. What matters is whether access, documentation, system knowledge and restart procedures actually exist and are usable. We help establish this second technical layer.
Are new devices integrated in a controlled way – or simply connected to the network?
Printers, cameras, gateways, scanners, IoT components or third-party systems can become poorly documented black boxes. We coordinate devices, deliver them preconfigured on request, inventory them and integrate them into network and security structures in a controlled way.
Do you receive documentation for Conditional Access, MFA or backup that you can use for your audit?
Yes. In addition to technical implementation, we can document the relevant configurations, responsibilities and technical information in a structured way so you can retain them internally and provide them to your auditor as an evidence basis.
Can riatech support us technically during a Part-IS audit?
Yes. On request, we are available for technical questions, explain infrastructure and configurations, provide agreed technical evidence and support the implementation of technical findings after the audit.
How can riatech support Part-IS implementation?
We combine technical assessment, implementation, documentation, ongoing operations and audit support. The goal is not theory, but a traceable technical baseline: know what exists, understand how it is connected, secure it, document it and operate it with evidence.
What role does riatech take specifically?
riatech supports the technical implementation and documentation of information security measures aligned with EASA Part-IS requirements – including identity & access, MFA, network segmentation, endpoint security, logging, monitoring, backup, patch management, remote access and incident response. Overall regulatory responsibility remains with the respective aviation organization.
