Navigate / EASA
GM1 IS.D.OR.235(a) Contracting of information security management activities

ED Decision 2023/009/R

PRIOR ASSESSMENT

The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the organisation, and may therefore be carried out in different ways, such as:

(a) in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers;

(b) review of the information security certifications granted by external and impartial auditors to the potential suppliers;

(c) review of self-assessment questionnaires compiled by the potential suppliers;

RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES

The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following:

(a) identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers;

(b) identification of the information security requirements of the organisation that are applicable to the contracted organisation;

(c) evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the contracting organisation;

(d) assessment of risks that may be introduced by the contracted organisation.

This agreed risk assessment should also consider the roles and responsibilities of the contracting and contracted organisation as well as their interfaces.