Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.220(a) Information security incidents -- detection, response and recovery
Available versions for ERULES-1963177438-21594
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.220(a) Information security incidents — detection, response and recovery ED Decision 2023/009/R DETECTION STRATEGY When developing the detection strategy, for those items within the scope of event detection, the organisation should define the conditions that trigger a process that, for example, would require personnel intervention and further analysis. These conditions on the items may be defined using elements from the: (a)    expected functional baseline: engage in the identification of deviations from the expected functional operation of the system (excluding information security functions/controls); (b)    expected information security baseline: engage in the identification of deviations from the expected information security operation of information security controls. These conditions should consider both abnormal behaviour and substantial deviations from the baselines and relevant correlation of multiple independent events. Further guidance on the objectives for the establishment of a detection strategy can be found in EUROCAE ED-206, Chapter 4.
##### GM1 IS.D.OR.220(a) Information security incidents — detection, response and recovery *ED Decision 2023/009/R* **DETECTION STRATEGY** When developing the detection strategy, for those items within the scope of event detection, the organisation should define the conditions that trigger a process that, for example, would require personnel intervention and further analysis. These conditions on the items may be defined using elements from the: (a) expected functional baseline: engage in the identification of deviations from the expected functional operation of the system (excluding information security functions/controls); (b) expected information security baseline: engage in the identification of deviations from the expected information security operation of information security controls. These conditions should consider both abnormal behaviour and substantial deviations from the baselines and relevant correlation of multiple independent events. Further guidance on the objectives for the establishment of a detection strategy can be found in EUROCAE ED-206, Chapter 4.