ED Decision 2023/009/R
EXAMPLES
The following Table 1 provides some examples of information security management activities that may be contracted in relation to the provisions referred to as in IS.D.OR.200.
Table 1: Examples of information security management activities that may be contracted
IS.D.OR.200 points related to activities |
Example of contracted activity |
(a)(1): establishes a policy on information security setting out the overall principles of the organisation with regard to the potential impact of information security risks on aviation safety; |
Information security policy drafting and consultancy |
(a)(2): identifies and reviews information security risks in accordance with point IS.D.OR.205; |
Identify activities, facilities and resources. Identify interfaces with other organisations which could be exposed to information security risks. Perform risk analysis or part of it, e.g. identify and classify information security risks. |
(a)(3) defines and implements information security risk treatment measures in accordance with point IS.D.OR.210; |
Define, develop and implement measures. Verify the initial and the continued effectiveness of the implemented measures (e.g. red-team/blue-team exercises, penetration testing, vulnerability scanning, etc.). Communicate to the involved stakeholders the outcome of the risk assessment and their responsibilities as part of the risk treatment process. |
(a)(4): implements an information security internal reporting scheme in accordance with point IS.D.OR.215; |
Define, develop and implement an internal reporting scheme to enable the collection and evaluation of information security events and vulnerabilities of equipment, processes and services. |
(a)(5): defines and implements, in accordance with point IS.D.OR.220, the measures required to detect information security events, identifies those events which are considered incidents with a potential impact on aviation safety except as permitted by point IS.D.OR.205 (e), and responds to, and recovers from, those information security incidents; |
Define, develop and implement measures to detect events. Define, develop and implement measures to respond to any event conditions. Define, develop and implement measures aimed at recovering from information security incidents. Implement immediate reaction measures to a information security incident or vulnerability as notified by the competent authority. |
(a)(6): implements the measures that have been notified by the competent authority as an immediate reaction to an information security incident or vulnerability with an impact on aviation safety; |
|
(a)(7): takes appropriate action, in accordance with point IS.D.OR.225, to address findings notified by the competent authority; |
Identify root cause. Define corrective action plan. Provide evidence of the corrective actions implemented to close the finding. |
(a)(8): implements an external reporting scheme in accordance with point IS.D.OR.230 in order to enable the competent authority to take appropriate actions; |
Define, develop and implement an external reporting scheme to enable the communication of the information security incidents and vulnerabilities of equipment, processes and services to the competent authority and when required to the design approval holder or the organisation responsible for the design. |
(a)(9): complies with the requirements contained in point IS.D.OR.235 when contracting any part of the activities described in point IS.D.OR.200 to other organisations; |
Not applicable |
(a)(10):complies with the personnel requirements contained in point IS.D.OR.240; |
Activities of the accountable manager / head of design organisation in the frame of the provisions for a ‘common responsible person’ as referred to in IS.D.OR.240 Compliance monitoring as foreseen by IS.D.OR.240 Contracted organisation to ensure that sufficient personnel is on duty to perform the activities related to this Regulation Define, develop and deliver adequate training to achieve the competencies required by the staff. Perform pre-employment checks |
(a)(11):complies with the record-keeping requirements contained in point IS.D.OR.245; |
Define, develop and implement secured archiving. Provision of secure data centre (as a service) Provision of records updates |
(a)(12):monitors compliance of the organisation with the requirements of this Regulation and provides feedback on findings to the accountable manager / head of design organisation to ensure effective implementation of corrective actions; |
Compliance monitoring (as foreseen by IS.D.OR.240) including the execution of independent audits |
(a)(13):protects, without prejudice to applicable incident reporting requirements, the confidentiality of any information that the organisation may have received from other organisations, according to its level of sensitivity. |
Define, develop and implement solutions to protect the confidentiality of any information. |
(b): In order to continuously meet the requirements referred to in Article 1, the organisation shall implement a continuous improvement process in accordance with point IS.D.OR.260. |
Execute independent effectiveness and maturity assessments. Define, develop and implement the necessary improvement measures. |
(c): The organisation shall document, in accordance with point IS.D.OR.250, all key processes, procedures, roles and responsibilities required to comply with point IS.D.OR.200(a), and shall establish a process for amending this documentation. Changes to those processes, procedures, roles and responsibilities shall be managed in accordance with point IS.D.OR.255. |
Production of documentation to detail all key processes, procedures, roles and responsibilities required to comply with point IS.D.OR.200(a) (e.g. information security policies, general description of the staff, procedures to specify compliance). Define, develop and implement processes for approving amendments and changes. |
Examples of contracted information security management activities under IS.D.OR.235, covering policy, risk, incidents, reporting, personnel, records, and compliance monitoring.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...