Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.205(a) Information security risk assessment
Available versions for ERULES-1963177438-21635
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.205(a) Information security risk assessment ED Decision 2023/009/R SCOPE AND BOUNDARIES IDENTIFICATION The organisation should develop clear and comprehensive understanding of its aviation activities and services, the related processes and associated information systems, and the relevant data flows and information exchanges that define the scope of the ISMS and the boundaries for risk assessment. Therefore, the organisation should develop corresponding documentation on resources and dependencies related to computing, networking and contracted services which have the potential to affect the information security and safety of the functions, services, or capabilities within the scope of the risk assessment. The following non-exhaustive list provides examples of items that may be considered for the identification of the aforementioned scope and boundaries. The level of detail of the analysis can be an iterative process, with the effort commensurate with the expected level of risk. As stated above, the purpose is to establish understanding of all relevant assets, resources and dependencies that are directly a part of the functions, services and capabilities through the following activities: (a) Identification of operational inputs and outputs relevant to the functions, services and capabilities of the organisation; these can be related to: — Internal or external sources; — internal or external leased or managed services, or other dependencies; (b) Identification of all relevant assets (i.e. hardware, software, network and computing resources) used to create, process, transmit, store or receive the aforementioned operational inputs and outputs; (c) Identification of the operating environments (e.g. office, public access area, access-controlled room etc.) and locations for all relevant assets; (d) For each asset included in the scope, identification of the specific methods, processes and resources that will be used to manage, operate and maintain each asset throughout its life cycle, including: — internal or contracted resources; — contracted companies remotely managing the assets (i.e. provider of managed services).
##### GM1 IS.D.OR.205(a) Information security risk assessment *ED Decision 2023/009/R* **SCOPE AND BOUNDARIES IDENTIFICATION** The organisation should develop clear and comprehensive understanding of its aviation activities and services, the related processes and associated information systems, and the relevant data flows and information exchanges that define the scope of the ISMS and the boundaries for risk assessment. Therefore, the organisation should develop corresponding documentation on resources and dependencies related to computing, networking and contracted services which have the potential to affect the information security and safety of the functions, services, or capabilities within the scope of the risk assessment. The following non-exhaustive list provides examples of items that may be considered for the identification of the aforementioned scope and boundaries. The level of detail of the analysis can be an iterative process, with the effort commensurate with the expected level of risk. As stated above, the purpose is to establish understanding of all relevant assets, resources and dependencies that are directly a part of the functions, services and capabilities through the following activities: (a) Identification of operational inputs and outputs relevant to the functions, services and capabilities of the organisation; these can be related to: — Internal or external sources; — internal or external leased or managed services, or other dependencies; (b) Identification of all relevant assets (i.e. hardware, software, network and computing resources) used to create, process, transmit, store or receive the aforementioned operational inputs and outputs; (c) Identification of the operating environments (e.g. office, public access area, access-controlled room etc.) and locations for all relevant assets; (d) For each asset included in the scope, identification of the specific methods, processes and resources that will be used to manage, operate and maintain each asset throughout its life cycle, including: — internal or contracted resources; — contracted companies remotely managing the assets (i.e. provider of managed services).