ED Decision 2023/009/R
SCOPE AND BOUNDARIES IDENTIFICATION
The organisation should develop clear and comprehensive understanding of its aviation activities and services, the related processes and associated information systems, and the relevant data flows and information exchanges that define the scope of the ISMS and the boundaries for risk assessment. Therefore, the organisation should develop corresponding documentation on resources and dependencies related to computing, networking and contracted services which have the potential to affect the information security and safety of the functions, services, or capabilities within the scope of the risk assessment.
The following non-exhaustive list provides examples of items that may be considered for the identification of the aforementioned scope and boundaries. The level of detail of the analysis can be an iterative process, with the effort commensurate with the expected level of risk. As stated above, the purpose is to establish understanding of all relevant assets, resources and dependencies that are directly a part of the functions, services and capabilities through the following activities:
(a) Identification of operational inputs and outputs relevant to the functions, services and capabilities of the organisation; these can be related to:
— Internal or external sources;
— internal or external leased or managed services, or other dependencies;
(b) Identification of all relevant assets (i.e. hardware, software, network and computing resources) used to create, process, transmit, store or receive the aforementioned operational inputs and outputs;
(c) Identification of the operating environments (e.g. office, public access area, access-controlled room etc.) and locations for all relevant assets;
(d) For each asset included in the scope, identification of the specific methods, processes and resources that will be used to manage, operate and maintain each asset throughout its life cycle, including:
— internal or contracted resources;
— contracted companies remotely managing the assets (i.e. provider of managed services).
Guidance on identifying ISMS scope and risk assessment boundaries, covering assets, operational inputs/outputs, environments, and lifecycle management resources.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...