Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.AR.210 Information security risk treatment
Available versions for ERULES-1963177438-19966
Regulation (EU) 2023/203
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.AR.210 Information security risk treatment Regulation (EU) 2023/203 (a) The competent authority shall develop measures to address unacceptable risks identified in accordance with point [IS.AR.205](#_DxCrossRefBm1193569464), shall implement them in a timely manner and shall check their continued effectiveness. Those measures shall enable the competent authority to: (1) control the circumstances that contribute to the effective occurrence of the threat scenario; (2) reduce the consequences to aviation safety associated with the materialisation of the threat scenario; (3) avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety. (b) The person referred to in point [IS.AR.225](#_DxCrossRefBm1193569459)(a) and other affected personnel of the competent authority shall be informed of the outcome of the risk assessment carried out in accordance with point [IS.AR.205](#_DxCrossRefBm1193569464), the corresponding threat scenarios and the measures to be implemented. The competent authority shall also inform organisations with which it has an interface in accordance with point [IS.AR.205](#_DxCrossRefBm1193569464)(b) of any risk shared between competent authority and the organisation.
#### IS.AR.210 Information security risk treatment *Regulation (EU) 2023/203* (a) The competent authority shall develop measures to address unacceptable risks identified in accordance with point [IS.AR.205](#_DxCrossRefBm1749084198), shall implement them in a timely manner and shall check their continued effectiveness. Those measures shall enable the competent authority to: (1) control the circumstances that contribute to the effective occurrence of the threat scenario; (2) reduce the consequences to aviation safety associated with the materialisation of the threat scenario; (3) avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety. (b) The person referred to in point [IS.AR.225](#_DxCrossRefBm1749084193)(a) and other affected personnel of the competent authority shall be informed of the outcome of the risk assessment carried out in accordance with point [IS.AR.205](#_DxCrossRefBm1749084198), the corresponding threat scenarios and the measures to be implemented. The competent authority shall also inform organisations with which it has an interface in accordance with point [IS.AR.205](#_DxCrossRefBm1749084198)(b) of any risk shared between competent authority and the organisation.