ED Decision 2023/009/R
Organisations may decide to outsource certain activities to suppliers, both for their own operational needs and for the purpose of complying with this Regulation (information security management activities). Activities contracted for operational needs may fall within the scope of Part-IS and therefore the relevant information security risks have to be managed in accordance with the requirements in points IS.D.OR.205 and IS.D.OR.210. Instead, information security management activities are subject to the specific provisions of IS.D.OR.235 because matters relating to these activities can have a major impact on the organisation.
Therefore the objectives of point IS.D.OR.235 are:
(a) to protect critical and sensitive information and assets when being handled by organisations contracted for the provision of information security management activities (including organisations in the supply chain) at either their facilities or the organisation facilities, or when being transmitted between the organisation and contracted organisations, or being remotely accessed by contracted organisations;
(b) to prevent information security risks from being introduced through products and services developed or provided by the contracted organisations to the organisation, in the frame of the provision of information security management activities;
(c) to ensure that information security risks are managed throughout all the stages of the relation with the contracted organisations.
Guidance on outsourcing information security management under Part-IS, covering protection of critical data, prevention of supply-chain risks, and risk management across all contract stages.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...