Navigate / EASA
GM5 IS.AR.220 Contracting of information security management activities

ED Decision 2023/010/R

AUDIT OF CONTRACTED ORGANISATIONS

The following aspects should be considered by the authority when auditing a supplier contracted to perform information security management activities:

β€” the scope of the audit as well as the objective should be limited to processes, resources (i.e. contracted organisation personnel, systems/equipment, networks) and data used for the execution of Part-IS contracted activities;

β€” compliance and/or implementation audits should be done at the authority’s discretion;

β€” findings identified during an audit should be addressed through a remediation plan with a time frame to be validated by the authority.