Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.235 Contracting of information security management activities
Available versions for ERULES-1963177438-21634
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.235 Contracting of information security management activities ED Decision 2023/009/R Organisations may decide to outsource certain activities to suppliers, both for their own operational needs and for the purpose of complying with this Regulation (information security management activities). Activities contracted for operational needs may fall within the scope of Part-IS and therefore the relevant information security risks have to be managed in accordance with the requirements in points [IS.D.OR.205](#_DxCrossRefBm1193569684) and [IS.D.OR.210](#_DxCrossRefBm1193569694). Instead, information security management activities are subject to the specific provisions of [IS.D.OR.235](#_DxCrossRefBm1193569690) because matters relating to these activities can have a major impact on the organisation. Therefore the objectives of point [IS.D.OR.235](#_DxCrossRefBm1193569690) are: (a) to protect critical and sensitive information and assets when being handled by organisations contracted for the provision of information security management activities (including organisations in the supply chain) at either their facilities or the organisation facilities, or when being transmitted between the organisation and contracted organisations, or being remotely accessed by contracted organisations; (b) to prevent information security risks from being introduced through products and services developed or provided by the contracted organisations to the organisation, in the frame of the provision of information security management activities; (c) to ensure that information security risks are managed throughout all the stages of the relation with the contracted organisations.
##### GM1 IS.D.OR.235 Contracting of information security management activities *ED Decision 2023/009/R* Organisations may decide to outsource certain activities to suppliers, both for their own operational needs and for the purpose of complying with this Regulation (information security management activities). Activities contracted for operational needs may fall within the scope of Part-IS and therefore the relevant information security risks have to be managed in accordance with the requirements in points [IS.D.OR.205](#_DxCrossRefBm1749084438) and [IS.D.OR.210](#_DxCrossRefBm1749084437). Instead, information security management activities are subject to the specific provisions of [IS.D.OR.235](#_DxCrossRefBm1749084433) because matters relating to these activities can have a major impact on the organisation. Therefore the objectives of point IS.D.OR.235 are: (a) to protect critical and sensitive information and assets when being handled by organisations contracted for the provision of information security management activities (including organisations in the supply chain) at either their facilities or the organisation facilities, or when being transmitted between the organisation and contracted organisations, or being remotely accessed by contracted organisations; (b) to prevent information security risks from being introduced through products and services developed or provided by the contracted organisations to the organisation, in the frame of the provision of information security management activities; (c) to ensure that information security risks are managed throughout all the stages of the relation with the contracted organisations.