Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.AR.225 Personnel requirements
Available versions for ERULES-1963177438-19969
Regulation (EU) 2023/203
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.AR.225 Personnel requirements Regulation (EU) 2023/203 The competent authority shall: (a) have a person who has the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this Regulation. This person shall: (1) have authority to fully access the resources necessary for the competent authority to perform all the tasks required by this Regulation; (2) possess the delegation of power required to perform the assigned duties; (b) have a process in place to ensure that they have sufficient personnel on duty to perform the activities covered by this Annex; (c) have a process in place to ensure that the personnel referred to in point (b) have the necessary competence to perform their tasks; (d) have a process in place to ensure that personnel acknowledge the responsibilities associated with the assigned roles and tasks; (e) ensure that the identity and trustworthiness of the personnel who have access to information systems and data subject to the requirements of this Regulation are appropriately established.
#### IS.AR.225 Personnel requirements *Regulation (EU) 2023/203* The competent authority shall: (a) have a person who has the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this Regulation. This person shall: (1) have authority to fully access the resources necessary for the competent authority to perform all the tasks required by this Regulation; (2) possess the delegation of power required to perform the assigned duties; (b) have a process in place to ensure that they have sufficient personnel on duty to perform the activities covered by this Annex; (c) have a process in place to ensure that the personnel referred to in point (b) have the necessary competence to perform their tasks; (d) have a process in place to ensure that personnel acknowledge the responsibilities associated with the assigned roles and tasks; (e) ensure that the identity and trustworthiness of the personnel who have access to information systems and data subject to the requirements of this Regulation are appropriately established.