Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.205(b) Information security risk assessment
Available versions for ERULES-1963177438-21640
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.205(b) Information security risk assessment ED Decision 2023/009/R RISK INFORMATION SHARING Interfacing organisations should share information with each other about the potential exposure to information security risks by following, for instance, the approach detailed in EUROCAE ED-201A, Appendix B — B.1, B.2 and B.3. The purpose of this exchange of information is to enable organisations to establish a matching mapping for the services identified under [IS.D.OR.205](#_DxCrossRefBm1193569684)(a), including all information and data flows, in order to: (a) illustrate (e.g. through a functional diagram) the relationships of logical and physical paths connecting the different parts involved; (b) clearly identify all assets (i.e. hardware, software, network and computing resources) that will be used in the exchange;; (c) identify all functions, activities and processes, including their respective information and data, which will be created, transmitted, processed, received and stored, and associate those with the responsible party which provides or performs those functions, activities and processes; (d) determine for these paths, constituting the so-called functional chains, the role of the interfacing party as a producer, processor, dispatcher or consumer of the information or data involved; (e) determine whether one interfacing party acts as an originator or receiver of a flow across such path. TWO CATEGORIES OF INTERFACING ORGANISATIONS There are two categories of interfacing organisations: those that are subject to Regulation (EU) 2023/203 or Regulation (EU) 2022/1645, and those that are not. Where the organisation has interfaces with an organisation that is subject to Regulation (EU) 2023/203 or Regulation (EU) 2022/1645, each entity: — is responsible for the identification of the interfaces that its own organisation has with other organisations, and which could result in the mutual exposure to information security risks. The entity may benefit from the sharing of risk information as this exchange allows for a more accurate assessment of those risks. — remains accountable for the proper management of the information security risks within the scope of its own ISMS. In all other cases, the organisation is accountable for the proper management of the information security risks that may arise from its exposure to the interfacing entity. Where these risks need to be treated, the organisation always has the option of implementing mitigating measures and controls within its own boundaries. In the specific case where the interfacing entity is a supplier, the organisation may decide to manage the risks through contractual arrangements and require the supplier to implement mitigating measures and controls within its own organisation.
##### GM1 IS.D.OR.205(b) Information security risk assessment *ED Decision 2023/009/R* **RISK INFORMATION SHARING** Interfacing organisations should share information with each other about the potential exposure to information security risks by following, for instance, the approach detailed in EUROCAE ED-201A, Appendix B — B.1, B.2 and B.3. The purpose of this exchange of information is to enable organisations to establish a matching mapping for the services identified under [IS.D.OR.205](#_DxCrossRefBm1749084438)(a), including all information and data flows, in order to: (a) illustrate (e.g. through a functional diagram) the relationships of logical and physical paths connecting the different parts involved; (b) clearly identify all assets (i.e. hardware, software, network and computing resources) that will be used in the exchange; (c) identify all functions, activities and processes, including their respective information and data, which will be created, transmitted, processed, received and stored, and associate those with the responsible party which provides or performs those functions, activities and processes; (d) determine for these paths, constituting the so-called functional chains, the role of the interfacing party as a producer, processor, dispatcher or consumer of the information or data involved; (e) determine whether one interfacing party acts as an originator or receiver of a flow across such path. **TWO CATEGORIES OF INTERFACING ORGANISATIONS** There are two categories of interfacing organisations: those that are subject to [Regulation (EU) 2023/203](http://data.europa.eu/eli/reg_impl/2023/203/oj) or [Regulation (EU) 2022/1645](http://data.europa.eu/eli/reg_del/2022/1645/oj), and those that are not. Where the organisation has interfaces with an organisation that is subject to Regulation (EU) 2023/203 or Regulation (EU) 2022/1645, each entity: — is responsible for the identification of the interfaces that its own organisation has with other organisations, and which could result in the mutual exposure to information security risks. The entity may benefit from the sharing of risk information as this exchange allows for a more accurate assessment of those risks. — remains accountable for the proper management of the information security risks within the scope of its own ISMS. In all other cases, the organisation is accountable for the proper management of the information security risks that may arise from its exposure to the interfacing entity. Where these risks need to be treated, the organisation always has the option of implementing mitigating measures and controls within its own boundaries. In the specific case where the interfacing entity is a supplier, the organisation may decide to manage the risks through contractual arrangements and require the supplier to implement mitigating measures and controls within its own organisation.