Navigate / EASA
GM1 IS.D.OR.220Ā Information security incidents — detection, response and recovery

ED Decision 2023/009/R

Without prejudice to the definition of ā€˜information security event’ in Article 3 of Regulation (EU) 2022/1645, those events that indicate the potential materialisation of unacceptable risks include both occurrences (i.e. anything that causes harm or have the potential to cause harm) and discovery of vulnerabilities. In fact, information security risks are associated with the potential that threats will exploit vulnerabilities, therefore the discovery of an exploitable vulnerability is an information security event.

In light of this, in the context of this Regulation:

— detection activities required under IS.D.OR.220(a) include vulnerability discovery;

— response activities under IS.D.OR.220(b) include vulnerability management.