Navigate / EASA
AMC1 IS.I.OR.205(e) Information security risk assessment

ED Decision 2023/009/R

SAFETY SUPPORT ASSESSMENT

Non-ATS providers should conduct a safety support assessment as it is described in Regulation
(EU) 2017/373
to assess the information security risk on their assets in regard to the service specification, e.g. integrity and availability, and to identify the residual risk.

The non-ATS provider should share with the ATS provider, in an appropriate form, information on the residual risk and the impact on the services it provides to that ATS provider.

The residual risk should be used to assess the potential impact on services and products that a non-ATS provider offers to an ATS provider.

The ATS provider can use this as an input for its security risk assessment and, more importantly, to evaluate the potential impacts of these residual risks on safety.