ED Decision 2023/009/R
If contracted organisations are also subject to this Regulation, the exchange of information and reporting should be covered under the management of shared risks and through the establishment of an external agreement between the organisations. Guidance regarding the development of external agreements can be found in EUROCAE ED-201A, Chapter 4.4 External agreements.
More in general, and in all other cases, any service contract should include standard clauses concerning obligations for the contracted organisation to:
— report within an agreed time information security incidents that may have an impact on the contracting organisation. Incidents and vulnerabilities which could lead to unsafe conditions should be reported as soon as possible and in such a manner that the external reporting obligation under IS.D.OR.230 can be ensured;
— designate a point of contact for the incident management and possible crisis management.
In some cases contracted organisations, such as service providers with distributed resources, may not be able to offer any ad hoc reporting. In these cases the internal reporting requirement may be fulfilled through other means that satisfy the objective of this provision. For instance, the contracted organisations may provide an up-to-date list of vulnerabilities affecting the systems within the scope of the contracted services. This list should be monitored by the contracting organisation as part of the internal reporting of information security events.
Guidance on information security internal reporting schemes for contracted organisations, covering external agreements, incident reporting clauses, and alternative vulnerability monitoring methods.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...