Navigate / EASA
GM1 IS.D.OR.255 Changes to the information security management system

ED Decision 2023/009/R

Point IS.D.OR.255 is structured as follows:

Point (a) introduces the possibility for the organisation to agree with the competent authority that changes to the ISMS can be implemented without prior approval as long as these changes are covered in a change procedure.

Point (b) introduces an obligation of prior approval (by the competent authority) for changes not covered by the procedure mentioned above, and indicates how those changes should be handled.

The organisation should consider the establishment of a procedure in order to manage and notify changes to the competent authority as provided for under IS.D.OR.255(a). In case of lack of any approved procedure, the organisation will have, for any change, to apply for and obtain an approval as required under IS.D.OR.255(b). In any case, all changes should be notified to the competent authority upon implementation.