Navigate / EASA
GM4 IS.AR.220 Contracting of information security management activities

ED Decision 2023/010/R

PRIOR ASSESSMENT

The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the competent authority, and may therefore be carried out in different ways, such as:

(a) in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers;

(b) review of the information security certifications granted by external and impartial auditors to the potential suppliers;

(c) review of self-assessment questionnaires compiled by the potential suppliers.

RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES

The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following:

(a) identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers;

(b) identification of the information security requirements of the authority that are applicable to the contracted organisation;

(c) evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the authority;

(d) assessment of risks that may be introduced by the contracted organisation.

This agreed risk assessment should also consider the roles and responsibilities of the parties (i.e. competent authority and contracted organisation) as well as their interfaces.