Navigate / EASA

Article 3 – Definitions

Regulation (EU) 2023/203

For the purpose of this Regulation, the following definitions shall apply:

(1) ‘information security’ means the preservation of confidentiality, integrity, authenticity and availability of network and information systems;

(2) ‘information security event’ means an identified occurrence of a system, service or network state indicating a possible breach of the information security policy or failure of information security controls, or a previously unknown situation that can be relevant for information security;

(3) ‘incident’ means any event having an actual adverse effect on the security of network and information systems as defined in Article 4(7) of Directive (EU) 2016/1148;

(4) ‘information security risk’ means the risk to organisational civil aviation operations, assets, individuals, and other organisations due to the potential of an information security event. Information security risks are associated with the potential that threats will exploit vulnerabilities of an information asset or group of information assets;

(5) ‘threat’ means a potential violation of information security which exists when there is an entity, circumstance, action or event that could cause harm;

(6) ‘vulnerability’ means a flaw or weakness in an asset or a system, procedures, design, implementation, or information security measures that could be exploited and results in a breach or violation of the information security policy.