Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.D.OR.210 Information security risk treatment
Available versions for ERULES-1963177438-19911
Regulation (EU) 2022/1645
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.D.OR.210 Information security risk treatment Regulation (EU) 2022/1645 (a) The organisation shall develop measures to address unacceptable risks identified in accordance with point [IS.D.OR.205](#_DxCrossRefBm1193569684), implement them in a timely manner and check their continued effectiveness. Those measures shall enable the organisation to: (1) control the circumstances that contribute to the effective occurrence of the threat scenario; (2) reduce the consequences on aviation safety associated with the materialisation of the threat scenario; (3) avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety. (b) The person referred to in point [IS.D.OR.240](#_DxCrossRefBm1193569689)(a) and (b) and other affected personnel of the organisation shall be informed of the outcome of the risk assessment carried out in accordance with point [IS.D.OR.205](#_DxCrossRefBm1193569684), the corresponding threat scenarios and the measures to be implemented. The organisation shall also inform organisations with which it has an interface in accordance with point [IS.D.OR.205](#_DxCrossRefBm1193569684)(b) of any risk shared between both organisations.
#### IS.D.OR.210 Information security risk treatment *Regulation (EU) 2022/1645* (a) The organisation shall develop measures to address unacceptable risks identified in accordance with point [IS.D.OR.205](#_DxCrossRefBm1749084438), implement them in a timely manner and check their continued effectiveness. Those measures shall enable the organisation to: (1) control the circumstances that contribute to the effective occurrence of the threat scenario; (2) reduce the consequences on aviation safety associated with the materialisation of the threat scenario; (3) avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety. (b) The person referred to in point [IS.D.OR.240](#_DxCrossRefBm1749084432)(a) and (b) and other affected personnel of the organisation shall be informed of the outcome of the risk assessment carried out in accordance with point IS.D.OR.205, the corresponding threat scenarios and the measures to be implemented. The organisation shall also inform organisations with which it has an interface in accordance with point IS.D.OR.205(b) of any risk shared between both organisations.