Navigate / EASA
GM2 IS.D.OR.205(d)Β Information security risk assessment

ED Decision 2023/009/R

The following are examples of changes that should be identified during the risk assessment review as they may trigger an update of the risk assessments:

(a) there is a change in the elements subject to information security risks as identified in IS.D.OR.205(a); a change in the elements will include:

β€” additions to, or removals from, the scope of the risk assessment of individual elements;

β€” changes to design or configuration of elements within the scope of the risk assessment that have the potential to alter the risk assessment outcomes; or

β€” changes to values, which would potentially trigger changes to impact levels, of elements within the scope of the risk assessment;

(b) there is a change in the interfaces between the organisation and other organisations with which the organisation shares information security risks or relies upon to mitigate information security risks (e.g. supply chains, service providers, cloud providers and customers), as identified in IS.D.OR.205(b), or between the system within the scope of the risk assessment and any other interconnected systems, or in the risks notified to the organisation by other organisations, as identified in IS.D.OR.205(b), or owners or managers of the other systems including:

β€” establishment of new interfaces;

β€” removal of existing interfaces;

β€” changes to existing interfaces that would have the potential to alter the risk assessment outcomes.

Note: Some organisational or system interconnections may be with organisations that are not within the scope of this Regulation as defined in Article 2 and therefore are not subject to the requirements of Part-IS. Where this is the case, these organisations should be informed of their responsibility to report such changes as listed above through contractual arrangement and reporting requirements between the affected organisations on a case-by-case basis and where applicable;

(c) there is a change in the information or knowledge used for the identification, analysis and classification of risks including:

β€” changes to threats and their values or addition of new threats that have not previously been assessed;

β€” changes to vulnerabilities or addition of new vulnerabilities that have not previously been assessed;

β€” changes in impacts or consequences of assessed threats or vulnerabilities;

β€” changes in aggregation of risks that may result in unacceptable levels of risks;

β€” changes or improvements in the risk management process, risk assessment approach and related activities;

β€” changes or improvements in the treatments of risks;

β€” changes in the criteria used to determine acceptance and treatments of risks;

(d) there are lessons learned from the analysis of information security incidents including:

β€” understanding why and how incidents have occurred; and

β€” reviewing all types of incidents including those due to external factors, technical reasons, human errors (inadvertent behaviour). For human intentional acts a distinction can be made between malign and benign actions.