Navigate / EASA
AMC1 IS.D.OR.200(a)(13) Information security management system (ISMS)

ED Decision 2023/009/R

When establishing compliance with the provisions under points IS.D.OR.200(a)(13), the organisation should implement and maintain information security controls that are sufficiently robust and effective to protect information and ensure the need-to-know principle (i.e. limiting access to information to only those who need it to perform their duties). It should protect the source of information in accordance with the relevant provisions established in Regulation (EU) 2018/1139. It should also comply with Regulation (EU) No 376/2014.