Regulation (EU) 2023/203
(a) In order to achieve the objectives set out in Article 1, the competent authority shall set up, implement and maintain an information security management system (ISMS) which ensures that the competent authority:
(1) establishes a policy on information security setting out the overall principles of the competent authority with regard to the potential impact of information security risks on aviation safety;
(2) identifies and reviews information security risks in accordance with point IS.AR.205;
(3) defines and implements information security risk treatment measures in accordance with point IS.AR.210;
(4) defines and implements, in accordance with point IS.AR.215, the measures required to detect information security events, identifies those which are considered incidents with a potential impact on aviation safety, and responds to, and recovers from, those information security incidents;
(5) complies with the requirements contained in point IS.AR.220 when contracting any part of the activities described in point IS.AR.200 to other organisations;
(6) complies with the personnel requirements contained in point IS.AR.225;
(7) complies with the record-keeping requirements contained in point IS.AR.230;
(8) monitors compliance of its own organisation with the requirements of this Regulation and provides feedback on findings to the person referred to in point IS.AR.225 (a) to ensure effective implementation of corrective actions;
(9) protects the confidentiality of any information that the competent authority may have related to organisations subject to its oversight and the information received through the organisation’s external reporting schemes established in accordance with point IS.I.OR.230 of Annex II (Part-IS.I.OR) to this Regulation and point IS.I.OR.230 of Annex I (Part-IS.I.OR) to Delegated Regulation (EU) 2022/1645;
(10) notifies the Agency of changes that affect the capacity of the competent authority to perform its tasks and discharge its responsibilities as defined in this Regulation;
(11) defines and implements procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other competent authorities and agencies, as well as organisations subject to this Regulation, to conduct effective security risk assessments relating to their activities.
(b) In order to continuously meet the requirements referred to in Article 1, the competent authority shall implement a continuous improvement process in accordance with point IS.AR.235.
(c) The competent authority shall document all key processes, procedures, roles and responsibilities required to comply with point IS.AR.200(a) and establish a process for amending this documentation.
(d) The processes, procedures, roles and responsibilities established by the competent authority in order to comply with point IS.AR.200(a) shall correspond to the nature and complexity of its activities, based on an assessment of the information security risks inherent to those activities, and may be integrated within other existing management systems already implemented by the competent authority.
Competent authorities must establish an ISMS covering policy, risk management, incident response, contracting, personnel, records, confidentiality, and continuous improvement under Regulation (EU) 2023/203.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...