ED Decision 2023/009/R
RISK INFORMATION SHARING
Interfacing organisations should share information with each other about the potential exposure to information security risks by following, for instance, the approach detailed in EUROCAE ED-201A, Appendix B — B.1, B.2 and B.3. The purpose of this exchange of information is to enable organisations to establish a matching mapping for the services identified under IS.D.OR.205(a), including all information and data flows, in order to:
(a) illustrate (e.g. through a functional diagram) the relationships of logical and physical paths connecting the different parts involved;
(b) clearly identify all assets (i.e. hardware, software, network and computing resources) that will be used in the exchange;
(c) identify all functions, activities and processes, including their respective information and data, which will be created, transmitted, processed, received and stored, and associate those with the responsible party which provides or performs those functions, activities and processes;
(d) determine for these paths, constituting the so-called functional chains, the role of the interfacing party as a producer, processor, dispatcher or consumer of the information or data involved;
(e) determine whether one interfacing party acts as an originator or receiver of a flow across such path.
TWO CATEGORIES OF INTERFACING ORGANISATIONS
There are two categories of interfacing organisations: those that are subject to Regulation (EU) 2023/203 or Regulation (EU) 2022/1645, and those that are not.
Where the organisation has interfaces with an organisation that is subject to Regulation (EU) 2023/203 or Regulation (EU) 2022/1645, each entity:
— is responsible for the identification of the interfaces that its own organisation has with other organisations, and which could result in the mutual exposure to information security risks. The entity may benefit from the sharing of risk information as this exchange allows for a more accurate assessment of those risks.
— remains accountable for the proper management of the information security risks within the scope of its own ISMS.
In all other cases, the organisation is accountable for the proper management of the information security risks that may arise from its exposure to the interfacing entity. Where these risks need to be treated, the organisation always has the option of implementing mitigating measures and controls within its own boundaries. In the specific case where the interfacing entity is a supplier, the organisation may decide to manage the risks through contractual arrangements and require the supplier to implement mitigating measures and controls within its own organisation.
Guidance on sharing risk information between interfacing organisations, including mapping data flows, identifying assets, and determining roles, plus accountability for managing risks with regulated and non-regulated ent
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...