Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.220(b) Information security incidents -- detection, response and recovery
Available versions for ERULES-1963177438-21598
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.220(b) Information security incidents — detection, response and recovery ED Decision 2023/009/R (a) INCIDENTS The organisation should take into account the following aspects when establishing compliance with the objectives contained in point [IS.D.OR.220](#_DxCrossRefBm1193569692)(b) relative to incidents: (1) Preparation of procedures and delineation of roles and responsibilities to respond in a timely, effective and orderly manner to any relevant information security incidents. (2) The response procedure should: (i) consider the warnings, unitary or combined, from [IS.D.OR.220](#_DxCrossRefBm1193569692)(a) (ii) establish, in accordance with [IS.D.OR.220](#_DxCrossRefBm1193569692)(b)(2), a containment strategy for each asset category considering the potential worst-case effect and the mission constraints, and provide criteria indicating when the incident is contained; (iii) define, in accordance with [IS.D.OR.220](#_DxCrossRefBm1193569692)(b)(3), the acceptable impact on safety and information security of each asset within the scope when they fail due to the materialisation of a threat scenario. (3) The response time should be commensurate with the impact level assessed in (2)(iii). (4) The response measures implemented under [IS.D.OR.220](#_DxCrossRefBm1193569692)(b) should be based on the response procedure referred to in the point (a)(2) and they should, in particular, consider the following: (i) the maximum acceptable safety level degradation of the assets within the scope of incident; (ii) the actions, such as resistance, containment, deception and control of the possible ways systems can fail, which will contribute to achieving the acceptable safety level degradation identified in point (i) while minimising the impact on operations; (iii) the resources required to implement the actions specified in point (ii). (5) The response time and the measures should take into account the potential immediate negative impact on safety if the measure is taken before it has been fully verified that it would not cause additional immediate safety impacts. (b) VULNERABILITIES The organisation should take into account the following aspects when establishing compliance with the objectives contained in point [IS.D.OR.220](#_DxCrossRefBm1193569692)(b) relative to vulnerabilities: (1) Establishment of a vulnerability management strategy defining procedures, roles and responsibilities to respond in a timely, effective and orderly manner to any detected relevant vulnerabilities. (2) The response measures implemented under point [IS.D.OR.220](#_DxCrossRefBm1193569692)(b) should be based on the maximum acceptable risk of the items within the scope of the vulnerability, considering the worst-case scenario of the vulnerability being exploited. (3) The response time should be commensurate with the pre-triage done on the warnings and the assessment of the potential impact of the vulnerability, if it is exploited.
##### AMC1 IS.D.OR.220(b) Information security incidents — detection, response and recovery *ED Decision 2023/009/R* **(a) INCIDENTS** The organisation should take into account the following aspects when establishing compliance with the objectives contained in point [IS.D.OR.220](#_DxCrossRefBm1749084435)(b) relative to incidents: (1) Preparation of procedures and delineation of roles and responsibilities to respond in a timely, effective and orderly manner to any relevant information security incidents. (2) The response procedure should: (i) consider the warnings, unitary or combined, from [IS.D.OR.220](#_DxCrossRefBm1749084435)(a) (ii) establish, in accordance with [IS.D.OR.220](#_DxCrossRefBm1749084435)(b)(2), a containment strategy for each asset category considering the potential worst-case effect and the mission constraints, and provide criteria indicating when the incident is contained; (iii) define, in accordance with [IS.D.OR.220](#_DxCrossRefBm1749084435)(b)(3), the acceptable impact on safety and information security of each asset within the scope when they fail due to the materialisation of a threat scenario. (3) The response time should be commensurate with the impact level assessed in (2)(iii). (4) The response measures implemented under [IS.D.OR.220](#_DxCrossRefBm1749084435)(b) should be based on the response procedure referred to in the point (a)(2) and they should, in particular, consider the following: (i) the maximum acceptable safety level degradation of the assets within the scope of incident; (ii) the actions, such as resistance, containment, deception and control of the possible ways systems can fail, which will contribute to achieving the acceptable safety level degradation identified in point (i) while minimising the impact on operations; (iii) the resources required to implement the actions specified in point (ii). (5) The response time and the measures should take into account the potential immediate negative impact on safety if the measure is taken before it has been fully verified that it would not cause additional immediate safety impacts. **(b) VULNERABILITIES** The organisation should take into account the following aspects when establishing compliance with the objectives contained in point [IS.D.OR.220](#_DxCrossRefBm1749084435)(b) relative to vulnerabilities: (1) Establishment of a vulnerability management strategy defining procedures, roles and responsibilities to respond in a timely, effective and orderly manner to any detected relevant vulnerabilities. (2) The response measures implemented under point [IS.D.OR.220](#_DxCrossRefBm1749084435)(b) should be based on the maximum acceptable risk of the items within the scope of the vulnerability, considering the worst-case scenario of the vulnerability being exploited. (3) The response time should be commensurate with the pre-triage done on the warnings and the assessment of the potential impact of the vulnerability, if it is exploited.