ED Decision 2023/010/R
Competent authorities may decide to outsource certain activities to suppliers, both for their own operational needs and for the purpose of complying with this Regulation (information security management activities). Activities contracted for operational needs may fall within the scope of Part-IS and therefore the relevant information security risks have to be managed in accordance with the requirements in points IS.AR.205 and IS.AR.210. Instead, information security management activities are subject to the specific provisions of IS.AR.220 because matters relating to these activities can have a major impact on the competent authority.
Therefore the objectives of point IS.AR.220 are:
(a) to protect critical and sensitive information and assets when being handled by organisations contracted for the provision of information security management activities (including organisations in the supply chain) at either their facilities or the competent authority facilities, or when being transmitted between the competent authority and contracted organisations, or being remotely accessed by contracted organisations;
(b) to prevent information security risks from being introduced through products and services developed or provided by the contracted organisations to the competent authority, in the frame of the provision of information security management activities;
(c) to ensure that information security risks are managed throughout all the stages of the relation with the contracted organisations.
Guidance on contracting information security management activities under IS.AR.220, covering objectives to protect sensitive data, prevent risks from contracted products and services, and manage risks throughout the outs
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...