Navigate / EASA
AMC1 IS.I.OR.210(a) Information security risk treatment

ED Decision 2023/009/R

(a) The risk treatment process should reach at least one of the objectives listed under IS.I.OR.210(a).

(b) When establishing compliance with the objectives under points IS.I.OR.210(a)(1) and IS.I.OR.210(a)(2), the organisation should take into account that:

(1) the measures developed under these points should be implemented according to a risk treatment plan with defined, risk-based priorities, objectives and agreed timelines and owners;

(2) life cycle considerations should be identified and associated to ensure continuous effectiveness of the information security measures including exchange of data with other entities;

(3) it should review and update the risk assessment, according to IS.I.OR.205(d), to evaluate whether the measures developed under these points introduce new unacceptable risks or modify existing risks in a way that they become unacceptable.

(c) Risk treatment should be documented and recorded, for example, in a risk registry, even if the risk has been avoided.