Social

Moldova aviation must implement mandatory ISMS for cyber security

Air operators, airports, and air navigation services providers, along with the Civil Aviation Authority (CAA) in the Republic of Moldova, must implement a complex Information Security Risk Management System (ISMS) to proactively combat cyberattacks and data leaks.

A regulation establishing this obligation was approved by the Government on November 12, proposed by the Ministry of Infrastructure and Regional Development (MIDR).

The Regulation focuses on information security risk management with a potential impact on aviation security. It provides for the establishment of a cohesive national information security management system in the Moldovan aviation sector, establishing clear roles for both the CAA and the Cyber Security Agency (ASC) to ensure a rapid and coordinated response to cybersecurity incidents.

Costs and Investments for Aviation Cyber Security

According to the project's explanatory note, implementing the Regulation will generate additional costs for authorities and operators, stemming from the need to acquire security technologies, personnel training, and comprehensive IT system audits.

"Initial costs will be covered from the current operational budgets of the targeted authorities and, potentially, through external support," the document specifies.

Estimated expenses vary across four key areas:

Procedures: 20,000 - 50,000 euros for developing and adjusting internal procedures.

Training: 10,000 - 30,000 euros for staff training.

Equipment: 30,000 - 80,000 euros for IT security equipment and technologies.

Compliance: 10,000 - 15,000 euros for audits and compliance.

The largest financial burden will be borne by the CAA and MoldATSA, with the combined financial impact estimated at 70,000 - 175,000 euros.

The Regulation will enter into force 12 months after its publication in the Official Monitor. During this grace period, institutions must train staff, acquire necessary cyber security technologies, and fully develop internal incident response procedures.

"Implementing this system will increase confidence in air services and contribute significantly to preventing risks that could affect passengers, aircraft, and aeronautical operations," the Ministry of Infrastructure and Regional Development stated.

The approved document effectively transposes two existing European regulations into national legislation concerning aviation safety and cyber protection.

Translation by Iurie Tataru

Bogdan Nigai

Bogdan Nigai

Author

Read more