Navigate / EASA
AMC1 IS.D.OR.200(a)(12) Information security management system (ISMS)

ED Decision 2023/009/R

COMPLIANCE MONITORING

When establishing compliance with the provisions under points IS.D.OR.200(a)(12) the organisation should implement a function to periodically monitor compliance of the management system with the relevant requirements and adequacy of the procedures including the establishment of an internal audit process and an information security risk management process. When the organisation has already established a compliance monitoring function under the implementing regulation for its domain, such function should include the monitoring of the management system with the relevant requirements within the scope of its activities. Compliance monitoring should include a feedback mechanism of audit findings to the accountable manager or, in the case of design organisations, to the head of the design organisation, or delegated persons to ensure implementation of corrective actions as necessary.