Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.AR.200 Information security management system (ISMS)
Available versions for ERULES-1963177438-19964
Regulation (EU) 2023/203
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.AR.200 Information security management system (ISMS) Regulation (EU) 2023/203 (a) In order to achieve the objectives set out in [Article 1](#_DxCrossRefBm1193569433), the competent authority shall set up, implement and maintain an information security management system (ISMS) which ensures that the competent authority: (1) establishes a policy on information security setting out the overall principles of the competent authority with regard to the potential impact of information security risks on aviation safety; (2) identifies and reviews information security risks in accordance with point [IS.AR.205](#_DxCrossRefBm1193569464); (3) defines and implements information security risk treatment measures in accordance with point [IS.AR.210](#_DxCrossRefBm1193569463); (4) defines and implements, in accordance with point [IS.AR.215](#_DxCrossRefBm1193569462), the measures required to detect information security events, identifies those which are considered incidents with a potential impact on aviation safety, and responds to, and recovers from, those information security incidents; (5) complies with the requirements contained in point [IS.AR.220](#_DxCrossRefBm1193569461) when contracting any part of the activities described in point [IS.AR.200](#_DxCrossRefBm1193569457) to other organisations; (6) complies with the personnel requirements contained in point [IS.AR.225](#_DxCrossRefBm1193569459); (7) complies with the record-keeping requirements contained in point [IS.AR.230](#_DxCrossRefBm1193569460); (8) monitors compliance of its own organisation with the requirements of this Regulation and provides feedback on findings to the person referred to in point [IS.AR.225](#_DxCrossRefBm1193569459) (a) to ensure effective implementation of corrective actions; (9) protects the confidentiality of any information that the competent authority may have related to organisations subject to its oversight and the information received through the organisation’s external reporting schemes established in accordance with point [IS.I.OR.230](#_DxCrossRefBm1193569432) of [Annex II (Part-IS.I.OR)](#_DxCrossRefBm1193569442) to this Regulation and point IS.I.OR.230 of Annex I (Part-IS.I.OR) to [Delegated Regulation (EU) 2022/1645](https://eur-lex.europa.eu/eli/reg_del/2022/1645/oj); (10) notifies the Agency of changes that affect the capacity of the competent authority to perform its tasks and discharge its responsibilities as defined in this Regulation; (11) defines and implements procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other competent authorities and agencies, as well as organisations subject to this Regulation, to conduct effective security risk assessments relating to their activities. (b) In order to continuously meet the requirements referred to in [Article 1](#_DxCrossRefBm1193569433), the competent authority shall implement a continuous improvement process in accordance with point [IS.AR.235](#_DxCrossRefBm1193569458). (c) The competent authority shall document all key processes, procedures, roles and responsibilities required to comply with point [IS.AR.200](#_DxCrossRefBm1193569457)(a) and establish a process for amending this documentation. (d) The processes, procedures, roles and responsibilities established by the competent authority in order to comply with point [IS.AR.200](#_DxCrossRefBm1193569457)(a) shall correspond to the nature and complexity of its activities, based on an assessment of the information security risks inherent to those activities, and may be integrated within other existing management systems already implemented by the competent authority.
#### IS.AR.200 Information security management system (ISMS) *Regulation (EU) 2023/203* (a) In order to achieve the objectives set out in [Article 1](#_DxCrossRefBm1749084164), the competent authority shall set up, implement and maintain an information security management system (ISMS) which ensures that the competent authority: (1) establishes a policy on information security setting out the overall principles of the competent authority with regard to the potential impact of information security risks on aviation safety; (2) identifies and reviews information security risks in accordance with point [IS.AR.205](#_DxCrossRefBm1749084198); (3) defines and implements information security risk treatment measures in accordance with point [IS.AR.210](#_DxCrossRefBm1749084197); (4) defines and implements, in accordance with point [IS.AR.215](#_DxCrossRefBm1749084196), the measures required to detect information security events, identifies those which are considered incidents with a potential impact on aviation safety, and responds to, and recovers from, those information security incidents; (5) complies with the requirements contained in point [IS.AR.220](#_DxCrossRefBm1749084195) when contracting any part of the activities described in point [IS.AR.200](#_DxCrossRefBm1749084191) to other organisations; (6) complies with the personnel requirements contained in point [IS.AR.225](#_DxCrossRefBm1749084193); (7) complies with the record-keeping requirements contained in point [IS.AR.230](#_DxCrossRefBm1749084194); (8) monitors compliance of its own organisation with the requirements of this Regulation and provides feedback on findings to the person referred to in point [IS.AR.225](#_DxCrossRefBm1749084193) (a) to ensure effective implementation of corrective actions; (9) protects the confidentiality of any information that the competent authority may have related to organisations subject to its oversight and the information received through the organisation’s external reporting schemes established in accordance with point [IS.I.OR.230](#_DxCrossRefBm1749084163) of [Annex II (Part-IS.I.OR)](#_DxCrossRefBm1749084173) to this Regulation and point IS.I.OR.230 of Annex I (Part-IS.I.OR) to [Delegated Regulation (EU) 2022/1645](https://eur-lex.europa.eu/eli/reg_del/2022/1645/oj); (10) notifies the Agency of changes that affect the capacity of the competent authority to perform its tasks and discharge its responsibilities as defined in this Regulation; (11) defines and implements procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other competent authorities and agencies, as well as organisations subject to this Regulation, to conduct effective security risk assessments relating to their activities. (b) In order to continuously meet the requirements referred to in [Article 1](#_DxCrossRefBm1749084164), the competent authority shall implement a continuous improvement process in accordance with point [IS.AR.235](#_DxCrossRefBm1749084192). (c) The competent authority shall document all key processes, procedures, roles and responsibilities required to comply with point [IS.AR.200](#_DxCrossRefBm1749084191)(a) and establish a process for amending this documentation. (d) The processes, procedures, roles and responsibilities established by the competent authority in order to comply with point [IS.AR.200](#_DxCrossRefBm1749084191)(a) shall correspond to the nature and complexity of its activities, based on an assessment of the information security risks inherent to those activities, and may be integrated within other existing management systems already implemented by the competent authority.