Navigate / EASA
GM1 IS.AR.205 Information security risk assessment

ED Decision 2023/010/R

Part-IS does not require the use of any specific information security framework, such as ISO, NIST or others to develop the risk assessment or in general to implement risk management. Each framework offers different benefits and none of these frameworks is perfect for an individual competent authority, and should be customised and tailored to meet the overall needs of a competent authority as well as the specific need to consider aviation safety aspects.

Competent authorities whose information security frameworks have achieved industry certifications can provide this information as supporting artefacts; however, these competent authorities should show the applicability of the industry certification to the scope of this Regulation (see GM1 IS.AR.200).

General guidance on risk management, including risk assessment, can be found in ISO/IEC 27005 and ISO/IEC 31000 as well as NIST SP 800-30. Competent authorities may also wish to consider aviation-specific guidance as defined in the risk management chapter of the latest version of EUROCAE ED-201A and, as appropriate to the specific operating environment, in the chapters of EUROCAE ED-204A, EUROCAE ED-205A and EUROCAE ED-206 covering risk management.