ED Decision 2025/014/R
Unacceptable risks identified in accordance with point IS.D.OR.205 require a risk treatment process that may lead to the introduction of information security measures, often referred to as information security controls.
For each identified risk, the organisation defines the specific risk treatment measures, methods or resources that will be used over the life cycle of each asset to:
— manage risk reduction;
— monitor and maintain each asset;
— update and fulfil activities for configuration management;
— manage supply chain;
— manage contracted services or service provider.
The review of risk treatment measures includes life cycle considerations which are introduced by equipment, procedures and personnel.
A risk treatment plan as an outcome of the risk management process includes a prioritisation of risks, the corresponding information on the objectives and means for risk treatment to reach an acceptable level of risk, as well as agreed timelines specifying when responsible personnel should have implemented the risk treatment measures. The timelines for the implementation of a risk treatment measure are subject to agreement by the personnel responsible for the implementation and are communicated to and accepted by the accountable manager or, in the case of design organisations, by the head of the design organisation, of the organisation or delegated person(s).
Any subsequent implementation delay, together with its cause, reason, rationale or necessity, is documented in the risk treatment plan, for risks that may lead to an unsafe condition. The delay is also subject to the acceptance by the accountable manager of the organisation, or by the head of the design organisation, or delegated person(s). This person may condition such acceptance on the implementation or availability of compensating controls or reactive measures to monitor, early detect and timely respond to the materialisation of the risk in treatment. In order to timely respond, the incident response team may be informed to trigger their preparedness.
The risk treatment plan can act as a means of communication with the competent authority to demonstrate effective treatment of unacceptable risks. Similarly, this plan can be utilised to communicate to interfacing organisations how shared risks are controlled.
In accordance with IS.D.OR.205(d), a regular or conditional review of the risk assessment is necessary, and this includes the review of the risk treatment measures developed under IS.D.OR.210(a) to identify whether they are still effective or they require adaptations.
In addition, the organisation should also consider the potential impact on the effectiveness of risk treatment measures where a shared information security risk may arise as a result of the interaction between interfacing entities (see IS.D.OR.235 and related AMC).
Guidance on information security risk treatment: defining measures, life cycle management, risk treatment plans, timeline acceptance, delay documentation, and communication with authorities and interfacing organisations.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...