ED Decision 2023/009/R
In order to comply with the provisions under IS.ID.OR.230 (a) and (b), the organisation should report:
(a) any occurrence covered by Regulation (EU) No 376/2014 that originated from intentional unauthorised electronic interactions;
(b) information security incidents having a potential significant risk to aviation safety not covered under Regulation (EU) No 376/2014;
(c) vulnerabilities that pose a significant risk to aviation safety and are not yet adequately mitigated in accordance with an approved vulnerability management strategy (see AMC1 IS.D.OR.220(b)).
From the aforementioned reports, it is the responsibility of the competent authorities under Part-IS to ensure compliance with Article 7 of this Regulation and to submit any relevant information that needs to be shared with the information security competent authorities designated under Article 8 of Directive (EU) 2016/1148.
Loading collections...