Skip to main content
EUROCONTROL
ELPAC

ELPAC Test Security Policy

How the ELPAC test platform, the testing process and candidate data are protected, and who is accountable for what.

Last reviewed: 29 August 2026

1. Purpose

ELPAC is the language proficiency test for aeronautical communication, owned by EUROCONTROL. The IT infrastructure is managed by ENOVATE on behalf of EUROCONTROL. ELPAC is operated to professional IT and process security standards: this policy sets out, in plain terms, the safeguards that protect the IT platform, the controls that govern the testing process, and the accountability of everyone who uses the system.

It gives EUROCONTROL, test centres and candidates assurance that ELPAC tests are delivered under controlled conditions and that candidate data is properly protected. It applies to the ELPAC test delivery platform and to everyone who uses it.

This policy is published on the ELPAC Portal so that it is available to all decision-makers, and it addresses the test security requirements set out in ICAO Doc 9835, section 6.3.5. See the ICAO Doc 9835 checklist for the item-by-item review.

2. IT security

The ELPAC platform runs on managed, professionally operated cloud infrastructure with load-balanced application environments and a managed database service. All hosting is located within the EU/EEA.

2.1 Protecting the platform

  • All data is encrypted in transit and at rest.
  • Production and non-production environments are kept separate. Live candidate data is never used outside production.
  • Systems and components are kept up to date through regular patching.
  • Activity is logged, and availability and error rates are monitored.
  • EUROCONTROL carries out periodic automated security scanning of the ELPAC environment, scheduled mainly outside test hours.

2.2 Access to the platform

  • Access is granted through named individual accounts only.
  • Permissions are role-based and follow the principle of least privilege: users can reach only what their role requires.
  • Multi-factor authentication is required for administrative access.
  • Access rights are removed when a person no longer needs them.

2.3 Backup and recovery

  • The database is backed up daily, so recent data can always be recovered (recovery point objective: 24 hours).
  • During test hours the service restoration target is 6 hours (recovery time objective), so testing can resume the same day.

3. Process security

Security depends as much on how the test is run as on the technology behind it.

3.1 Change and release control

  • Changes to the platform follow a controlled release process: they are reviewed and tested before being applied to production.
  • Changes that could affect a live test session are scheduled outside test hours.

3.2 Security of test material

  • Only the dedicated sample tests published on the ELPAC Portal are public. They are produced specifically for publication and are not used as live test material.
  • Live Paper 1 items, and Paper 2 scripts, prompts and answer keys, are held in confidence. They are not published and are not made available to candidates before the test event.
  • Paper 1 test forms are assembled from a calibrated item bank, and Paper 2 uses several scripted scenarios per role, so no single version of the test is exposed to the whole candidate population.
  • Everyone handling live test material is bound by confidentiality obligations and may not copy, retain or share it outside the test process.

3.3 Handling candidate data

  • Candidate identity is verified before the test begins.
  • Candidate data is collected only where it is needed to deliver and certify the test.
  • Paper 2 is audio-recorded, and the recording is kept as part of the candidate test record.

3.4 Release of results

  • Results are held in strict confidence and are released only to the ELPAC test centre administrator.
  • The test centre administrator is responsible for reporting the score to the candidate and, where applicable, to the licensing authority.
  • Results are not released to any other person or organisation without the written permission of the candidate.

3.5 Data retention

ELPAC data retention periods
DataRetention
Test results and scores10 years after the test session; 50 years where ICAO Level 6 is awarded
Examiner evaluation records and supporting documentation10 years after the test session; 50 years where ICAO Level 6 is awarded
Audio recordings of Paper 210 years after the test session; 50 years where ICAO Level 6 is awarded
System and access logs12 months

These periods ensure that rating decisions remain verifiable and that scores remain available for the duration of the licence. Data is securely deleted once its retention period has passed.

3.6 Vulnerabilities and incidents

The ELPAC environment is monitored continuously and scanned periodically. Anything found through scanning, testing or reporting is classified by severity and remediated within defined targets:

Remediation targets by severity
SeverityRemediation target
CriticalWithin 7 days
HighWithin 30 days
Medium and lowAt the next scheduled release

Suspected security incidents are reported immediately to the supplier and to EUROCONTROL. Where an incident involves personal data, EUROCONTROL is notified within 24 hours of the incident being identified so that any further notification obligations can be met.

4. People using the system

Every action in ELPAC is carried out by a known person with a defined role.

4.1 Who does what

Roles and responsibilities
RoleResponsibility
EUROCONTROLOwns ELPAC and this policy; oversees security and carries out periodic security scanning.
ENOVATE (supplier)Operates and maintains the platform, applies technical controls, reports incidents.
Test centresRun test sessions locally, manage their own users, verify candidate identity, report results.
Test administrators and examinersSupervise the test session, safeguard test material and confirm the session is conducted under the required conditions.
CandidatesSit the test under the published conditions and use only their own account.

4.2 Accounts and accountability

  • Individual accounts only; shared logins are not permitted.
  • Credentials must never be shared, written down in accessible places or reused elsewhere.
  • All actions in the system are logged and attributable to a named user.
  • Test centres are responsible for requesting the removal of accounts for staff who leave or change role.

4.3 During the test session

  • Tests are administered by trained test administrators and examiners in a private, quiet and suitably equipped location.
  • The test administrator confirms the candidate's identity before the test starts.
  • The test administrator remains present and supervises the session throughout.
  • Only the equipment required for the test is used; unauthorised devices and materials are not permitted.
  • Paper 2 is audio-recorded so that the conduct of the session and the rating decision can be verified.
  • Any irregularity or suspected malpractice is recorded and reported.
  • Test centres operate under the ELPAC Licence Agreement and under the oversight of their local competent authority.

4.4 Confidentiality and awareness

  • Everyone with access to ELPAC test material or candidate data is bound by confidentiality obligations.
  • Staff are made aware of their security responsibilities before being given access.

5. Review and related documents

This policy should be read together with the ELPAC Handbook (test administration, test centre requirements and appeals), the ELPAC Assessment Scheme (rating and score reporting) and the ELPAC Licence Agreement (obligations of user organisations), all available in the document library, and the ELPAC Code of Ethics.

This policy is reviewed periodically and updated to reflect changes in the ELPAC platform, the testing process and applicable requirements.

Related pages

Continue reading