Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.255 Changes to the information security management system
Available versions for ERULES-1963177438-21639
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.255 Changes to the information security management system ED Decision 2023/009/R Without prejudice to the communication of changes as required for each organisation in the corresponding implementing regulation for the domain as listed in point Article 2(1) of Regulation (EU) 2022/1645, the procedure referred to in [IS.D.OR.255](#_DxCrossRefBm1193569686)(a)(1) should take into account the criticality of the changes when proposing how they will be managed. In particular, those changes that could have an impact on the achievement or maintenance of compliance with the provisions under Part-IS, or which could lead to an unacceptable level of risk (e.g. as per the guidance provided in GM1 [IS.D.OR.205](#_DxCrossRefBm1193569684)(c)), should be subjected to scrutiny. Upon establishment of this procedure, any further changes to it should be subject to approval by the competent authority. Where prior approval is sought from the competent authority for a change not covered by an approved procedure, or where no such approved procedure exists, the organisation should provide at least the following information: — the nature and purpose of the change; — the implementation plan of the change; — the verification plan of the change; — the potential impact on aviation safety introduced by the change. A significant deviation from the original implementation plan during the change process is an event that should be reported to the competent authority as this deviation may require reconsidering the change impact.
##### AMC1 IS.D.OR.255 Changes to the information security management system *ED Decision 2023/009/R* Without prejudice to the communication of changes as required for each organisation in the corresponding implementing regulation for the domain as listed in point Article 2(1) of [Regulation (EU) 2022/1645](http://data.europa.eu/eli/reg_del/2022/1645/oj), the procedure referred to in [IS.D.OR.255](#_DxCrossRefBm1749084428)(a) should take into account the criticality of the changes when proposing how they will be managed. In particular, those changes that could have an impact on the achievement or maintenance of compliance with the provisions under Part-IS, or which could lead to an unacceptable level of risk (e.g. as per the guidance provided in GM1 [IS.D.OR.205](#_DxCrossRefBm1749084438)(c)), should be subjected to scrutiny. Upon establishment of this procedure, any further changes to it should be subject to approval by the competent authority. Where prior approval is sought from the competent authority for a change not covered by an approved procedure, or where no such approved procedure exists, the organisation should provide at least the following information: — the nature and purpose of the change; — the implementation plan of the change; — the verification plan of the change; — the potential impact on aviation safety introduced by the change. A significant deviation from the original implementation plan during the change process is an event that should be reported to the competent authority as this deviation may require reconsidering the change impact.