Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.AR.205 Information security risk assessment
Available versions for ERULES-1963177438-19965
Regulation (EU) 2023/203
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.AR.205 Information security risk assessment Regulation (EU) 2023/203 (a) The competent authority shall identify all the elements of its own organisation which could be exposed to information security risks. This shall include: (1) the competent authority’s activities, facilities and resources, and the services the competent authority operates, provides, receives or maintains; (2) the equipment, systems, data and information that contribute to the functioning of the elements referred to in point (1) (b) The competent authority shall identify the interfaces that its own organisation has with other organisations, and which could result in the mutual exposure to information security risks. (c) For the elements and interfaces referred to in points (a) and (b), the competent authority shall identify the information security risks which may have a potential impact on aviation safety. For each identified risk, the competent authority shall: (1) assign a risk level according to a predefined classification established by the competent authority; (2) associate each risk and its level with the corresponding element or interface identified in accordance with points (a) and (b). The predefined classification referred to in point (1) shall take into account the potential of occurrence of the threat scenario and the severity of its safety consequences. Through this classification, and taking into account whether the competent authority has a structured and repeatable risk management process for operations, the competent authority shall be able to establish whether the risk is acceptable or needs to be treated in accordance with point [IS.AR.210](#_DxCrossRefBm1193569463). In order to facilitate the mutual comparability of risks assessments, the assignment of the risk level per point (1) shall take into account relevant information acquired in coordination with the organisations referred to in point (b). (d) The competent authority shall review and update the risk assessment carried out in accordance with points (a), (b) and (c) in any of the following cases: (1) there is a change in the elements subject to information security risks; (2) there is a change in the interfaces between the competent authority’s organisation and other organisations, or in the risks communicated by the other organisations; (3) there is a change in the information or knowledge used for the identification, analysis and classification of risks; (4) there are lessons learnt from the analysis of information security incidents.
#### IS.AR.205 Information security risk assessment *Regulation (EU) 2023/203* (a) The competent authority shall identify all the elements of its own organisation which could be exposed to information security risks. This shall include: (1) the competent authority’s activities, facilities and resources, and the services the competent authority operates, provides, receives or maintains; (2) the equipment, systems, data and information that contribute to the functioning of the elements referred to in point (1) (b) The competent authority shall identify the interfaces that its own organisation has with other organisations, and which could result in the mutual exposure to information security risks. (c) For the elements and interfaces referred to in points (a) and (b), the competent authority shall identify the information security risks which may have a potential impact on aviation safety. For each identified risk, the competent authority shall: (1) assign a risk level according to a predefined classification established by the competent authority; (2) associate each risk and its level with the corresponding element or interface identified in accordance with points (a) and (b). The predefined classification referred to in point (1) shall take into account the potential of occurrence of the threat scenario and the severity of its safety consequences. Through this classification, and taking into account whether the competent authority has a structured and repeatable risk management process for operations, the competent authority shall be able to establish whether the risk is acceptable or needs to be treated in accordance with point [IS.AR.210](#_DxCrossRefBm1749084197). In order to facilitate the mutual comparability of risks assessments, the assignment of the risk level per point (1) shall take into account relevant information acquired in coordination with the organisations referred to in point (b). (d) The competent authority shall review and update the risk assessment carried out in accordance with points (a), (b) and (c) in any of the following cases: (1) there is a change in the elements subject to information security risks; (2) there is a change in the interfaces between the competent authority’s organisation and other organisations, or in the risks communicated by the other organisations; (3) there is a change in the information or knowledge used for the identification, analysis and classification of risks; (4) there are lessons learnt from the analysis of information security incidents.