Navigate / EASA
GM2 IS.D.OR.235(a) Contracting of information security management activities

ED Decision 2023/009/R

AUDIT OF CONTRACTED ORGANISATIONS

The following aspects should be considered by the organisation when auditing a supplier contracted to perform information security management activities:

โ€” the scope of the audit as well as the objective should be limited to processes, resources (i.e. contracted organisation personnel, systems/equipment, networks) and data used for the execution of Part-IS contracted activities;

โ€” compliance and/or implementation audits should be done at the contracting organisationโ€™s discretion;

โ€” findings identified during an audit should be addressed through a remediation plan with a time frame to be validated by the contracting organisation.