Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.240(e) Personnel requirements
Available versions for ERULES-1963177438-21595
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.240(e) Personnel requirements ED Decision 2023/009/R COMMON RESPONSIBLE PERSON If a common responsible person (CRP) is delegated by the accountable manager or, in the case of design organisations, by the head of the design organisation for the activities under this Regulation, this person should also be given the appropriate delegation that is necessary to implement the provisions of [IS.D.OR.200](#_DxCrossRefBm1193569683), including the authority and the financial means to mobilise and control the resources across the organisations, or parts of the organisation involved. This delegation may also include the appointment of the person or group of persons referred to in [IS.D.OR.240](#_DxCrossRefBm1193569689)(b) and (c) and, in general, the CRP may be assisted in the performance of his or her duties by additional personnel. The possibility of delegating a CRP applies to an organisation that shares information security organisational structures, policies, processes and procedures with other organisations or with parts of its own organisation that are not part of the authorisation or declaration, and therefore this CRP is expected to have information security responsibilities and competencies. In particular, the CRP should be capable of managing the organisation’s information security strategy and its implementation to ensure the achievement of the objectives described in Article 1. According to the European Cybersecurity Skills Framework (ECSF) published by ENISA in September 2022, this person may be described, for instance, as (Chief) Information Security Officer, Cybersecurity Programme Director or Information Security Manager. However, it should be noticed that these descriptions and the related skills do not consider the aviation safety perspective that is required in Article 1. Where an entity holds multiple authorisations or declarations, the relevant accountable managers or, in the case of design organisations, the relevant head of the design organisations may delegate to the same CRP, who will therefore be responsible for implementing the provisions of [IS.D.OR.200](#_DxCrossRefBm1193569683) for a functional cluster sharing information security structures, policies, processes and procedures.
##### GM1 IS.D.OR.240(e) Personnel requirements *ED Decision 2023/009/R* **COMMON RESPONSIBLE PERSON** If a common responsible person (CRP) is delegated by the accountable manager or, in the case of design organisations, by the head of the design organisation for the activities under this Regulation, this person should also be given the appropriate delegation that is necessary to implement the provisions of [IS.D.OR.200](#_DxCrossRefBm1749084427), including the authority and the financial means to mobilise and control the resources across the organisations, or parts of the organisation involved. This delegation may also include the appointment of the person or group of persons referred to in [IS.D.OR.240](#_DxCrossRefBm1749084432)(b) and (c) and, in general, the CRP may be assisted in the performance of his or her duties by additional personnel. The possibility of delegating a CRP applies to an organisation that shares information security organisational structures, policies, processes and procedures with other organisations or with parts of its own organisation that are not part of the authorisation or declaration, and therefore this CRP is expected to have information security responsibilities and competencies. In particular, the CRP should be capable of managing the organisation’s information security strategy and its implementation to ensure the achievement of the objectives described in Article 1. According to the European Cybersecurity Skills Framework (ECSF) published by ENISA in September 2022, this person may be described, for instance, as (Chief) Information Security Officer, Cybersecurity Programme Director or Information Security Manager. However, it should be noticed that these descriptions and the related skills do not consider the aviation safety perspective that is required in Article 1. Where an entity holds multiple authorisations or declarations, the relevant accountable managers or, in the case of design organisations, the relevant head of the design organisations may delegate to the same CRP, who will therefore be responsible for implementing the provisions of [IS.D.OR.200](#_DxCrossRefBm1749084427) for a functional cluster sharing information security structures, policies, processes and procedures.