ED Decision 2023/009/R
Without prejudice to the communication of changes as required for each organisation in the corresponding implementing regulation for the domain as listed in point Article 2(1) of Regulation (EU) 2022/1645, the procedure referred to in IS.D.OR.255(a) should take into account the criticality of the changes when proposing how they will be managed. In particular, those changes that could have an impact on the achievement or maintenance of compliance with the provisions under Part-IS, or which could lead to an unacceptable level of risk (e.g. as per the guidance provided in GM1 IS.D.OR.205(c)), should be subjected to scrutiny. Upon establishment of this procedure, any further changes to it should be subject to approval by the competent authority.
Where prior approval is sought from the competent authority for a change not covered by an approved procedure, or where no such approved procedure exists, the organisation should provide at least the following information:
— the nature and purpose of the change;
— the implementation plan of the change;
— the verification plan of the change;
— the potential impact on aviation safety introduced by the change.
A significant deviation from the original implementation plan during the change process is an event that should be reported to the competent authority as this deviation may require reconsidering the change impact.
AMC1 IS.D.OR.255 guides organisations on managing information security management system changes, emphasising criticality-based scrutiny, approval of procedure changes, and reporting significant deviations to the Competo
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...