Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.230(a)&(b) Information security external reporting scheme
Available versions for ERULES-1963177438-21622
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.230(a)&(b) Information security external reporting scheme ED Decision 2023/009/R In order to comply with the provisions under [IS.ID.OR.230](#_DxCrossRefBm1193569509) (a) and (b), the organisation should report: (a) any occurrence covered by Regulation (EU) No 376/2014 that originated from intentional unauthorised electronic interactions; (b) information security incidents having a potential significant risk to aviation safety not covered under Regulation (EU) No 376/2014; (c) vulnerabilities that pose a significant risk to aviation safety and are not yet adequately mitigated in accordance with an approved vulnerability management strategy (see [AMC1 IS.D.OR.220(b)](#_DxCrossRefBm1193569740)). From the aforementioned reports, it is the responsibility of the competent authorities under Part-IS to ensure compliance with [Article 7](#_DxCrossRefBm1193569445) of this Regulation and to submit any relevant information that needs to be shared with the information security competent authorities designated under Article 8 of Directive (EU) 2016/1148.
##### AMC1 IS.D.OR.230(a)&(b) Information security external reporting scheme *ED Decision 2023/009/R* In order to comply with the provisions under [IS.ID.OR.230](#_DxCrossRefBm1749084243) (a) and (b), the organisation should report: (a) any occurrence covered by Regulation (EU) No 376/2014 that originated from intentional unauthorised electronic interactions; (b) information security incidents having a potential significant risk to aviation safety not covered under Regulation (EU) No 376/2014; (c) vulnerabilities that pose a significant risk to aviation safety and are not yet adequately mitigated in accordance with an approved vulnerability management strategy (see [AMC1 IS.D.OR.220(b)](#_DxCrossRefBm1749084485)). From the aforementioned reports, it is the responsibility of the competent authorities under Part-IS to ensure compliance with [Article 7](#_DxCrossRefBm1749084179) of this Regulation and to submit any relevant information that needs to be shared with the information security competent authorities designated under Article 8 of Directive (EU) 2016/1148.