Navigate / EASA
GM1 IS.AR.205(d) Information security risk assessment

ED Decision 2023/010/R

The criteria to consider for the frequency of the risk assessment review may be the risk level as well as the criticality and complexity of the assets concerned. The objective of a risk assessment review is to trigger the revaluation of risks, their likelihood and impact in case of relevant changes. One possible way is to have a tiered approach to risk assessment, with a higher-level risk assessment being used for the identification of changes. The higher-level risk assessment could allow the identification of the detailed risks that should be reviewed in a next step. Risk assessments should be subject to regular reviews to:

(a) allow for continuous improvement of the quality of risk assessment;

(b) ensure efficiency and effectiveness of risk controls and mitigating measures in both their design and operation;

(c) review plans and actions for risk treatment;

(d) identify any organisational change which may require a review of the priorities as well as of the treatment of risks;

(e) maintain an overview of the complete risk picture; and

(f) identify any emerging risks.

Risk assessment reviews should involve the risk owners, project teams and other stakeholders as applicable. Evidence of risk assessment review should be documented and should include:

β€” evidence of approval of the review by the designated risk owner; and

β€” the rationale behind or basis for the risk owner’s approval of the review.

Such evidence may comprise, but is not limited to:

β€” reports which constitute a form of documentation to track information security risks potentially impacting an organisation;

β€” the documentation of the information security risk assessment;

β€” exerts from a business or security risk registry.

The periodicity of risk assessment reviews should be documented by the authority in information security manuals, processes or procedures and should align with wider change management activities and management reviews of information security. Further guidance on criteria and frequency of risk assessment review can be found in EUROCAE ED-201A Chapter 4, as well as in EUROCAE ED-205A, Chapter 3.2 (for ATMS/ANS).