ED Decision 2023/010/R
PROPORTIONALITY IN ISMS IMPLEMENTATION
When implementing the processes and procedures, as well as establishing the roles and responsibilities required under point IS.AR.200(d), the competent authority should primarily consider the risks that it may be posing to other organisations, as well as its own risk exposure. Other aspects that may be relevant include the authority’s needs and objectives, information security requirements, its own processes, and the size, complexity and structure of the authority, all of which may change over time.
INTEGRATION OF ISMS UNDER THIS REGULATION WITH EXISTING MANAGEMENT SYSTEMS
A competent authority may take advantage of existing management systems when implementing an ISMS by integrating it with those existing systems.
By integrating the ISMS with existing management systems, the competent authority may reduce the effort and costs required to implement and maintain the ISMS, while also ensuring consistency and alignment with the authority’s overall management approach. Below is a non-exhaustive list of potential synergies that can be exploited when integrating the ISMS with an existing management system:
— Leverage existing policies and procedures: an authority may use its existing policies and procedures as a foundation for its ISMS. This may help to ensure consistency and minimise the need for additional documentation.
— Align the ISMS with other management systems: an authority may align the ISMS with other management systems, such as safety management systems (SMSs), to ensure that the ISMS is consistent with the authority’s overall management approach.
— Use existing risk management processes: an authority may use their existing risk management processes to identify and assess the information security risks potentially leading to aviation safety risks.
— Reuse existing controls: an authority may reuse existing controls, such as access controls or incident management process, to implement the information security controls required by the ISMS.
— Continuous improvement process: an authority may use the continuous improvement process of existing management systems to improve the ISMS over time.
Guidance on implementing an information security management system under IS.AR.200(d), focusing on proportionality, risk consideration, and integration with existing management systems to reduce effort and costs.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...