INDUSTRIES SERVED

CAA ASSURE Auditing

Today’s Aviation sector relies on a technology backed world. Maintaining safe, secure, and resilient operations is your focus and our number one priority when assisting Aviation organisations.

Contact our Aviation Cyber Security Experts

Civil Aviation Authority

The Civil Aviation Authority (CAA) is the UK’s Aviation regulator. It is responsible for the regulation of Aviation safety in the UK, determining policy for the use of airspace, the economic regulation of Heathrow, Gatwick and Stansted airports, the licencing and financial fitness of airlines and the management of the ATOP financial protection scheme for holidaymakers.

The CAA Cyber Security Oversight Team is responsible for all cyber security regulatory activity within any of the CAA regulatory domains. All organisations in scope of the Cyber Security Oversight Process CAP1753 must partner with an accredited CAA ASSURE organisation in order to conduct their cyber security audits.

YOUR AVIATION CYBER SECURITY STRATEGY

The multi-faceted and multi-disciplinary nature of Aviation cyber security means that it is critical to develop a common vision for defining a global cyber security strategy. Aligning with local and international Aviation security and management provisions, your cyber security strategy should evolve around the following components – 

CAA ASSURE Cyber Audits

Released in 2020 by the Civil Aviation Authority, CAA Assure is a third-party cyber security audit scheme that has been developed in partnership with CREST to provide rigorous and continuous audits to organisations in the Aviation sector. 

As a regulatory responsibility, Aviation organisations must ensure they meet the oversight responsibilities that fall under CAP 1753 – ‘The Cybersecurity Oversight Process for Aviation’. This is a six-step approach to ensuring cyber security oversight for Aviation organisations operating within the United Kingdom. 

 

These six steps include:

All UK Aviation organisations in scope of the cyber security oversight process for Aviation (CAP 1753), will need to procure cyber audit services from an accredited ASSURE Cyber Supplier. As one of only a small number of ASSURE and CREST accredited providers in the UK, Dionach have demonstrated extensive knowledge in the following three ASSURE Specialisms: Cyber Audit & Risk Management, Technical Cyber Security and ICS/OT. As such, we are ideally positioned to assist Aviation organisations with preparing to meet the continuously changing and rigorous Aviation standards and regulations. 

For further information on the implementation of a CAA ASSURE audit, speak to our team to discuss howe we work with you to implement an ASSURE audit.

Compliance service

How are Dionach positioned to help Aviation Organisations?

Dionach’s cyber security experts have a solid history of experience working with Civil Aviation and other transport sectors, delivering safe audits of critical Operational Technology (OT) and Process Control Networks (PCNs). As a trusted cyber security partner for Aviation organisations, our long standing 20-year background, combined with our in-house innovation and research team, enable us to stay on top of the latest cyber security threats to the Aviation sector. 

Get a Quote our Aviation Cyber Security Experts

OUR ACCREDITATIONS

CAA Assure

As one of only a small number of UK ASSURE accredited providers, Dionach have shown specialist knowledge in the areas of Cyber Audit & Risk Management, Technical Cyber Security Expert and ICS/OT Expert and are ideally placed to provide Aviation cyber security services.

PCI QSA

Dionach have been deemed by the PCI Security Standards Council to meet specific information security education requirements and have taken the appropriate training from the PCI Security Standards Council to be able to effectively perform PCI compliance assessments.

ISO 27001

Upholding the same rigorous standards we deploy to our clients, Dionach are ISO 27001 certified, reflecting our dedication to upholding the highest Information Security Management standards in accordance with the latest regulations and recommendations.

CREST

Dionach are certified by CREST for Vulnerability Assessments, Intelligence Led Penetration Testing (STAR), Cyber Security Incident Response (CSIR), and Penetration Testing. Our CREST qualified consultants include CREST Practitioner Security Analysts, CREST Registered Penetration Testers, CREST Certified Infrastructure Testers and CREST Certified Web Application Testers.

CHECK

Dionach are a NCSC CHECK Green Light provider of manual Penetration Testing services. We are experienced in identifying security weaknesses and vulnerabilities in the target systems and producing a comprehensive and detailed report in line with NCSC’s requirements, outlining the issues identified and practical recommendations on how to resolve them.

HOW WE WORK

We deliver the whole spectrum of cyber security services, from long-term, enterprise wide strategy and implementation projects to single penetration tests.

Our team works with you to identify and assess your organisation’s vulnerabilities, define enterprise-wide goals, and advise how best to achieve them.

Our recommendations are clear, concise, pragmatic and tailored to your organisation.

Independent, unbiased, personalised – this is how we define our services. We guide you to spend wisely and invest in change efficiently.

Find out how we can help with your cyber challenge

dISCOVER OUR LATEST RESEARCH

AdobeStock_499513355

ISO 27001 Implementation: Common Challenges and How to Overcome Them

ISO 27001 is an internationally recognised standard for information security management, offering a comprehensive framework to help organisations manage and protect their sensitive information. As data breaches and cybersecurity threats continue to rise, more businesses are adopting ISO 27001 to safeguard their assets, reputation, and customer trust. However, implementing ISO 27001 can be a challenging […]
AdobeStock_112344183

How to Fast-Track Your PCI DSS v4.0 Compliance

The Payment Card Industry Data Security Standard (PCI DSS) has long been the benchmark for organisations that handle cardholder data, providing a framework for securing payment systems and protecting sensitive information.   With the release of PCI DSS vv4.0, organisations must adapt to the updated requirements or risk facing significant fines for non-compliance. As the […]
AdobeStock_541508167

Navigating Data Protection Regulations and Compliance

Data protection regulations are crucial in today’s digital age, especially for industries like healthcare that handle sensitive information. Understanding and complying with these regulations can be daunting, but it’s essential for safeguarding data and maintaining trust. This article will help you navigate data protection regulations and compliance with practical tips and tools. Understanding Data Protection […]
Contact Us

Contact Us Reach out to one of our cyber experts and we will arrange a call