Navigate / EASA
AMC1 IS.I.OR.200(c) Information security management system (ISMS)

ED Decision 2023/009/R

When establishing compliance with the provisions under point IS.I.OR.200(c), the organisation should:

(a) provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities. This outline of the structure will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the accountable manager. The organisation should review the outline of the structure at planned intervals or if significant changes occur (see the Note in AMC1 IS.I.OR.200(a)(1));

(b) identify and categorise all relevant contracted organisations used to implement the ISMS. The organisation should define and document procedures for the management of interfaces and coordination between the organisation and other organisations, including contracted organisations;

(c) identify and define all key processes and procedures, and internal and external reporting schemes, that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The organisation may adjust existing processes or procedures for compliance;

(d) identify and document any other information that will be used to maintain compliance with the objectives of this Regulation;

(e) when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy;

(f) control the documented information required by the ISMS to ensure that it is:

(1) available and suitable for use, where and when it is needed;

(2) adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).