ED Decision 2023/009/R
If a common responsible person (CRP) is delegated by the accountable manager or, in the case of design organisations, by the head of the design organisation for the activities under this Regulation, this person should also be given the appropriate delegation that is necessary to implement the provisions of IS.D.OR.200, including the authority and the financial means to mobilise and control the resources across the organisations, or parts of the organisation involved. This delegation may also include the appointment of the person or group of persons referred to in IS.D.OR.240(b) and (c) and, in general, the CRP may be assisted in the performance of his or her duties by additional personnel.
The possibility of delegating a CRP applies to an organisation that shares information security organisational structures, policies, processes and procedures with other organisations or with parts of its own organisation that are not part of the authorisation or declaration, and therefore this CRP is expected to have information security responsibilities and competencies. In particular, the CRP should be capable of managing the organisation’s information security strategy and its implementation to ensure the achievement of the objectives described in Article 1. According to the European Cybersecurity Skills Framework (ECSF) published by ENISA in September 2022, this person may be described, for instance, as (Chief) Information Security Officer, Cybersecurity Programme Director or Information Security Manager. However, it should be noticed that these descriptions and the related skills do not consider the aviation safety perspective that is required in Article 1.
Where an entity holds multiple authorisations or declarations, the relevant accountable managers or, in the case of design organisations, the relevant head of the design organisations may delegate to the same CRP, who will therefore be responsible for implementing the provisions of IS.D.OR.200 for a functional cluster sharing information security structures, policies, processes and procedures.
Guidance on delegating a common responsible person (CRP) for information security under IS.D.OR.200, including authority, financial means, and ECSF role examples, with aviation safety caveat.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...