Navigate / EASA
AMC1 IS.I.OR.205(b) Information security risk assessment

ED Decision 2023/009/R

The organisation should, as part of the information security risk assessment, identify the interfaces it has with other parties such as service providers, supply chains and other third parties, based on the exchange of data and information and the assets used for that exchange, which could lead to a situation where information security risks, as a result of mutual exposure, may either:

— increase aviation safety risks faced by other parties; and/or

— increase aviation safety risks faced by the organisation.