ED Decision 2023/009/R
The organisation should use a risk management framework that includes a methodology for assigning risks with a risk level and establishing criteria for determining risk acceptance or further treatment.
The organisation should provide documented evidence of assessment of risks which have a potential impact on aviation safety including the level of risks. The organisation should associate each risk with the relevant elements and interfaces identified under IS.D.OR.205 (a) and (b), and document whether the risk is acceptable or requires further treatment.
The organisation should provide the assurance that the risk assessment process is carried out with the necessary rigour and discipline by documenting the process and its robustness. By doing so, the organisation should consider:
(a) reproducibility of the assessment’s results for similar inputs;
(b) repeatability of the assessment over time in a way that the results of the different prior assessments can be compared to determine the changes;
(c) the gathering of inputs that are relevant and valid, in particular:
(1) the information that allows the determination of the safety consequences;
(2) the information that allows the determination of the potential of occurrence of the threat scenario;
(d) iterative refinement over time allowing for more fine-grained threat scenarios as inputs become available, with the aimof reducing uncertainty regarding threats, vulnerabilities, effectiveness of existing controls, and dependencies on external entities, in particular by:
(1) refining initial high-level threat scenarios with greater detail and specificity as more data is gathered;
(2) refining data on known vulnerabilities by continuously updating information about their exploitability and the associated consequences;
(3) reviewing the effectiveness of existing controls, and consider newly available controls;
(4) refining the understanding of the dependencies on external entities and their implications for the organisation’s risk profile.
AMC1 IS.D.OR.205(c) requires a risk management framework with risk levels, acceptance criteria, documented evidence, and rigorous, reproducible, repeatable, and iteratively refined assessments.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...