Navigate / EASA
GM1 IS.D.OR.200(e) Information security management system (ISMS)

ED Decision 2025/014/R

Any organisation that believes that it does not pose any information security risk with a potential impact on aviation safety, either to itself or to other organisations, may consider requesting an approval for a derogation by the competent authority following the procedure outlined in AMC1 IS.D.OR.200(e).

Existing safety risk assessments, such as those carried out as part of the SMS, can form the basis of enhanced assessments considering safety risks arising from information security threats.

It should be noted that applications for partial exemption from individual articles are not possible.

APPLICATION FOR A DEROGATION

In order to ensure a consistent approach by organisations when submitting a derogation request, the competent authority may establish an official derogation request application form.

The application for a derogation, based on the application form where one exists or in a format decided by the organisation, will need to be signed by the accountable manager of the applicant organisation and submitted to the appropriate competent authority for review and consideration.

The application for a derogation should contain preliminary information used for a pre-assessment by the competent authority, including:

— Company information and contact information;

— Affected approval(s);

— Detailed justification for the exclusion of the provisions;

— Overview of services that the organisation provides and receives;

— Architecture overview of information systems used for business operation;

— Summary of the high-level information security risk assessment aligned with the above architecture;

— Methodology used to perform the information security risk assessment;

— List of people and roles involved in the information security risk assessment process;

— Date and signature.

Note: At this stage, the high-level risk assessment needs to properly document the absence of information security risks that may impact safety. To do so, it should at least cover the identification of the scope and boundaries, as required under points IS.D.OR.205 (a) and (b), and the analysis of safety impact, as required under point IS.D.OR.205(c).

EVALUATION OF THE REQUEST FOR A DEROGATION

The competent authority reviews the information security risk assessment and other supporting documentation, normally assessing whether:

— the documentation is sufficient for a proper analysis and assessment;

— the repository or asset inventory of digital systems, data flows and processes is comprehensive;

— the high-level information security risk assessment has been conducted in accordance with the organisation’s methodology and with the appropriate diligence;

— the relevant stakeholders have been involved in the assessment process;

— the assessment has been performed by people with sufficient expertise in information security and aviation safety;

— the organisation has assigned and indicated a point of contact for enquiries.

Figure 1 below depicts the process, including the pre-assessment. If the pre-assessment provides the competent authority with sufficient evidence that the derogation request is legitimate and that the organisation meets the expected criteria, the process will proceed to the exchange of more detailed information.

Figure 1: Representation of the derogation process

Note 1 to Figure 1: The objective of this step is to obtain preliminary information about the organisation risk profile by using suitable means (e.g. questionnaire, self-assessment template, request tool, etc.)

Note 2 to Figure 1: The objective of this step is to conduct a pre-evaluation to check whether the organisation has the possibility to be granted a derogation. The pre-assessment allows to avoid a detailed assessment if the prerequisites for a derogation are not met.



EXPECTATIONS AND RECOMMENDATION AFTER DEROGATION APPROVAL

Once a derogation approval has been granted, the organisation is expected to undertake the following on a continuous basis:

— Comply with all provisions of the regulation which are not exempted, in particular point IS.D.OR.200(a)(13) which should not be limited to only protection of the received information. When transmitting information with confidential nature, the organisation needs to have secure means in place as well;

— Comply with Regulation (EU) No 376/2014 to take into account the obligation to comply with the reporting requirements.

— Monitor any changes in the organisation’s scope of work and identify those which may have a potential impact on the documented information, which supports the derogation approval. Where such changes are identified, the organisation should ensure that they are brought to the attention of the competent authority without delay and notified in accordance with the applicable implementing rule.

— Monitor the risk picture for any variation due to changes in the safety and security environment over time. To this end, point IS.D.OR.205(d) should be considered.

— Ensure that the accountable manager or the head of the design of the organisation can demonstrate an understanding of the derogation process and the terms on which the approval has been granted. This means that at least one person in the organisation needs to have a basic understanding of the Regulation. To this end, point IS.D.OR.240(a)(3) and the related AMC and GM should be considered.

— Implement basic protection against information security risks according to industry best practices.

— Remain up to date with the latest information security threat landscape and consult the respective national authority for additional guidance.

EXAMPLES

An example of organisations that may consider asking for a derogation might include DOA or POA holders that design or produce only components or parts that either are not involved in ensuring the structural integrity of the aircraft (e.g. carpets, interiors) or have no major safety-related aircraft functionalities, including but not limited to, aircraft software, navigation, avionics, engines, flight control, landing gear, hydraulic, electrical, air, communications, etc.

The aforementioned example is only indicative of a potential scenario that might provide an initial basis for the preparation of an information security risk assessment that justifies the exclusion of all elements of an organisation from the scope of the ISMS.