ATCO.AR.A.025A Immediate reaction to an information security
incident or vulnerability with an impact on aviation safety
Regulation (EU) 2023/203
(a) The competent authority shall implement a system to
appropriately collect, analyse, and disseminate information related to
information security incidents and vulnerabilities with a potential impact on
aviation safety that are reported by organisations. This shall be done in
coordination with any other relevant authorities responsible for information
security or cybersecurity within the Member State to increase the coordination
and compatibility of reporting schemes.
(b) The Agency shall implement a system to appropriately analyse
any relevant safety-significant information received in accordance with point ATCO.AR.A.020,
and without undue delay provide the Member States and the Commission with any
information, including recommendations or corrective actions to be taken,
necessary for them to react in a timely manner to an information security
incident or vulnerability with a potential impact on aviation safety involving
products, parts, non-installed equipment, persons or organisations subject to Regulation
(EU) 2018/1139 and its delegated and
implementing acts.
(c) Upon receiving the information referred to in points (a) and
(b), the competent authority shall take adequate measures to address the
potential impact on aviation safety of the information security incident or
vulnerability.
(d) Measures taken in accordance with point (c) shall immediately
be notified to all persons or organisations that shall comply with them under
Regulation (EU) 2018/1139 and its delegated and implementing acts. The
competent authority of the Member State shall also notify those measures to
the Agency and, when combined action is required, the competent authorities of
the other Member States concerned.
[applicable from 22
February 2026 – Regulation (EU) 2023/203]
EASA aviation regulations mandate immediate action for information security incidents impacting aviation safety. Authorities must collect, analyze, and share incident data, coordinating with cybersecurity agencies. The European Union Aviation Safety Agency (EASA) analyzes safety information, providing recommendations to member states. Authorities must implement measures and notify relevant parties to mitigate potential risks.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...