Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.250(a) Information security management manual (ISMM)
Available versions for ERULES-1963177438-21636
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.250(a) Information security management manual (ISMM) ED Decision 2023/009/R The organisation may choose to document some of the information required under point [IS.D.OR.250](#_DxCrossRefBm1193569687)(a) in separate documents (e.g. procedures). In this case, it should ensure that the manual contains adequate references to any document kept separately. Any such documents are then to be considered an integral part of the organisation’s information security management system manual. In the event where an entity holds multiple authorisations or declarations, the ISMM may apply to one or more organisations at a time based on a common ISMS. This ISMM should include at least an approval document of each organisation and should formally be approved by each organisation’s accountable manager or, in the case of design organisations, by each head of the design organisations or responsible person. A common responsible person may be appointed as per [IS.D.OR.240](#_DxCrossRefBm1193569689)(d) and the guidelines of [GM1 IS.D.OR.240(e)](#_DxCrossRefBm1193569773). To ensure that all parties involved can fulfil their responsibilities, all manuals, procedures, and communication between them are advised to be, at least, in one common language, e.g. English. Those parties involved include the competent authorities with which that common language should be agreed upon.
##### GM1 IS.D.OR.250(a) Information security management manual (ISMM) *ED Decision 2023/009/R* The organisation may choose to document some of the information required under point [IS.D.OR.250](#_DxCrossRefBm1749084429)(a) in separate documents (e.g. procedures). In this case, it should ensure that the manual contains adequate references to any document kept separately. Any such documents are then to be considered an integral part of the organisation’s information security management system manual. In the event where an entity holds multiple authorisations or declarations, the ISMM may apply to one or more organisations at a time based on a common ISMS. This ISMM should include at least an approval document of each organisation and should formally be approved by each organisation’s accountable manager or, in the case of design organisations, by each head of the design organisations or responsible person. A common responsible person may be appointed as per [IS.D.OR.240](#_DxCrossRefBm1749084432)(d) and the guidelines of [GM1 IS.D.OR.240(e)](#_DxCrossRefBm1749084518). To ensure that all parties involved can fulfil their responsibilities, all manuals, procedures, and communication between them are advised to be, at least, in one common language, e.g. English. Those parties involved include the competent authorities with which that common language should be agreed upon.