Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.D.OR.220 Information security incidents -- detection, response and recovery
Available versions for ERULES-1963177438-19913
Regulation (EU) 2022/1645
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.D.OR.220 Information security incidents — detection, response and recovery Regulation (EU) 2022/1645 (a) Based on the outcome of the risk assessment carried out in accordance with point [IS.D.OR.205](#_DxCrossRefBm1193569684) and the outcome of the risk treatment performed in accordance with point [IS.D.OR.210](#_DxCrossRefBm1193569694), the organisation shall implement measures to detect incidents and vulnerabilities that indicate the potential materialisation of unacceptable risks and which may have a potential impact on aviation safety. Those detection measures shall enable the organisation to: (1) identify deviations from predetermined functional performance baselines; (2) trigger warnings to activate proper response measures, in case of any deviation. (b) The organisation shall implement measures to respond to any event conditions identified in accordance with point (a) that may develop or have developed into an information security incident. Those response measures shall enable the organisation to: (1) initiate the reaction to the warnings referred to in point (a)(2) by activating predefined resources and course of actions; (2) contain the spread of an attack and avoid the full materialisation of a threat scenario; (3) control the failure mode of the affected elements defined in point [IS.D.OR.205](#_DxCrossRefBm1193569684)(a). (c) The organisation shall implement measures aimed at recovering from information security incidents, including emergency measures, if needed. Those recovery measures shall enable the organisation to: (1) remove the condition that caused the incident, or constrain it to a tolerable level; (2) reach a safe state of the affected elements defined in point [IS.D.OR.205](#_DxCrossRefBm1193569684)(a) within a recovery time previously defined by the organisation.
#### IS.D.OR.220 Information security incidents — detection, response and recovery *Regulation (EU) 2022/1645* (a) Based on the outcome of the risk assessment carried out in accordance with point [IS.D.OR.205](#_DxCrossRefBm1749084438) and the outcome of the risk treatment performed in accordance with point [IS.D.OR.210](#_DxCrossRefBm1749084437), the organisation shall implement measures to detect incidents and vulnerabilities that indicate the potential materialisation of unacceptable risks and which may have a potential impact on aviation safety. Those detection measures shall enable the organisation to: (1) identify deviations from predetermined functional performance baselines; (2) trigger warnings to activate proper response measures, in case of any deviation. (b) The organisation shall implement measures to respond to any event conditions identified in accordance with point (a) that may develop or have developed into an information security incident. Those response measures shall enable the organisation to: (1) initiate the reaction to the warnings referred to in point (a)(2) by activating predefined resources and course of actions; (2) contain the spread of an attack and avoid the full materialisation of a threat scenario; (3) control the failure mode of the affected elements defined in point IS.D.OR.205(a). (c) The organisation shall implement measures aimed at recovering from information security incidents, including emergency measures, if needed. Those recovery measures shall enable the organisation to: (1) remove the condition that caused the incident, or constrain it to a tolerable level; (2) reach a safe state of the affected elements defined in point IS.D.OR.205(a) within a recovery time previously defined by the organisation.