Acts Online
GT Shield

Civil Aviation Act, 2009 (Act No. 13 of 2009)

Regulations

Civil Aviation Regulations, 2011

Part 109 : Aviation Security Training Organisations

Subpart 3 : Instructor Certification

109.03.10 Measures to mitigate threats of cyber-attacks

 

(1) An ASTO shall—
(a) identify and secure its critical information and communication technology systems and data used for aviation purposes to ensure cybersecurity, privacy, and resilience as prescribed in Document SA-CATS 109;
(b) ensure that its cybersecurity measures are in accordance with risk assessment and threat levels;
(c) implement cybersecurity measures as prescribed in Document SA-CATS 109; and
(d) report any cybersecurity incident as prescribed in Document SA-CATS 109 to the Director within 48 hours of becoming aware of such incident.

[Regulation 109.03.10(1) substituted by section 16(a) of the Thirty-Third Amendment of the Civil Aviation Regulations, 2026, Notice No. 7844, GG55226, dated 21 August 2026 and shall come into operation upon Publication in the Government Gazette, save for Part 92, which shall come into operation upon the Proclamation by the President of the Civil Aviation Amendment Act, 2021 (Act No. 22 of 2021]

 

(2) An ASTO shall develop procedures for—
(a) testing of cyber-security;
(b) cyber-security response;
(c) cyber-security incident analysis; and
(d) cyber-security incident reporting.

 

(3) An ASTO shall report any cyber-security  incident to the Director within 48 hours of occurrence.

 

[Regulation 109.03.10 inserted by regulation 27(a) and 27(f) of Notice No. R.1503, GG45491, dated 15 November 2021 (Twenty-First Amendment of the Civil Aviation Regulations, 2021)]