Navigate / EASA
AMC1 IS.I.OR.245(a)(1)(vi)&(a)(5) Record-keeping

ED Decision 2023/009/R

When complying with the requirements under points (a)(1)(vi) and (a)(5), the organisation should establish a data retention policy defining procedures to:

(a) manage relevant security data files;

(b) establish the periodical assessment of their content; and

(c) define the criteria to allow deletion of records of information security events when the objective of the requirement under (a)(5) has been met.