Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM3 IS.D.OR.235 Contracting of information security management activities
Available versions for ERULES-1963177438-21641
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM3 IS.D.OR.235 Contracting of information security management activities ED Decision 2023/009/R EXAMPLES The following Table 1 provides some examples of information security management activities that may be contracted in relation to the provisions referred to as in [IS.D.OR.200](#_DxCrossRefBm1193569683). *Table 1: Examples of information security management activities that may be contracted* <table border="1" cellpadding="0" cellspacing="0" width="604"> <thead> <tr> <td valign="top" width="302"> <p align="center"><a href="#_DxCrossRefBm1193569683">IS.D.OR.200</a> points related to activities</p> </td> <td valign="top" width="302"> <p align="center">Example of contracted activity</p> </td> </tr> </thead> <tr> <td valign="top" width="302"> <p>(a)(1): establishes a policy on information security setting out the overall principles of the organisation with regard to the potential impact of information security risks on aviation safety;</p> </td> <td valign="top" width="302"> <p>Information security policy drafting and consultancy</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(2): identifies and reviews information security risks in accordance with point <a href="#_DxCrossRefBm1193569684">IS.D.OR.205</a>;</p> </td> <td valign="top" width="302"> <p>Identify activities, facilities and resources.</p> <p>Identify interfaces with other organisations which could be exposed to information security risks.</p> <p>Perform risk analysis or part of it, e.g. identify and classify information security risks.</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(3) defines and implements information security risk treatment measures in accordance with point <a href="#_DxCrossRefBm1193569694">IS.D.OR.210</a>;</p> </td> <td valign="top" width="302"> <p>Define, develop and implement measures.</p> <p>Verify the initial and the continued effectiveness of the implemented measures (e.g. red-team/blue-team exercises, penetration testing, vulnerability scanning, etc.).</p> <p>Communicate to the involved stakeholders the outcome of the risk assessment and their responsibilities as part of the risk treatment process.</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(4): implements an information security internal reporting scheme in accordance with point <a href="#_DxCrossRefBm1193569693">IS.D.OR.215</a>;</p> </td> <td valign="top" width="302"> <p>Define, develop and implement an internal reporting scheme to enable the collection and evaluation of information security events and vulnerabilities of equipment, processes and services.</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(5): defines and implements, in accordance with point <a href="#_DxCrossRefBm1193569692">IS.D.OR.220</a>, the measures required to detect information security events, identifies those events which are considered incidents with a potential impact on aviation safety except as permitted by point <a href="#_DxCrossRefBm1193569684">IS.D.OR.205</a> (e), and responds to, and recovers from, those information security incidents;</p> </td> <td rowspan="2" valign="top" width="302"> <p>Define, develop and implement measures to detect events.</p> <p>Define, develop and implement measures to respond to any event conditions.</p> <p>Define, develop and implement measures aimed at recovering from information security incidents.</p> <p>Implement immediate reaction measures to a information security incident or vulnerability as notified by the competent authority. </p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(6): implements the measures that have been notified by the competent authority as an immediate reaction to an information security incident or vulnerability with an impact on aviation safety;</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(7): takes appropriate action, in accordance with point <a href="#_DxCrossRefBm1193569691">IS.D.OR.225</a>, to address findings notified by the competent authority;</p> </td> <td valign="top" width="302"> <p>Identify root cause.</p> <p>Define corrective action plan.</p> <p>Provide evidence of the corrective actions implemented to close the finding. </p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(8): implements an external reporting scheme in accordance with point <a href="#_DxCrossRefBm1193569509">IS.D.OR.230</a> in order to enable the competent authority to take appropriate actions;</p> </td> <td valign="top" width="302"> <p>Define, develop and implement an external reporting scheme to enable the communication of the information security incidents and vulnerabilities of equipment, processes and services to the competent authority and when required to the design approval holder or the organisation responsible for the design.</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(9): complies with the requirements contained in point <a href="#_DxCrossRefBm1193569690">IS.D.OR.235</a> when contracting any part of the activities described in point <a href="#_DxCrossRefBm1193569683">IS.D.OR.200</a> to other organisations;</p> </td> <td valign="top" width="302"> <p>Not applicable</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(10): complies with the personnel requirements contained in point <a href="#_DxCrossRefBm1193569689">IS.D.OR.240</a>;</p> </td> <td valign="top" width="302"> <p>Activities of the accountable manager / head of design organisation in the frame of the provisions for a ‘common responsible person’ as referred to in <a href="#_DxCrossRefBm1193569689">IS.D.OR.240</a></p> <p>Compliance monitoring as foreseen by <a href="#_DxCrossRefBm1193569689">IS.D.OR.240</a></p> <p>Contracted organisation to ensure that sufficient personnel is on duty to perform the activities related to this Regulation </p> <p>Define, develop and deliver adequate training to achieve the competencies required by the staff.</p> <p>Perform pre-employment checks</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(11): complies with the record-keeping requirements contained in point <a href="#_DxCrossRefBm1193569688">IS.D.OR.245</a>;</p> </td> <td valign="top" width="302"> <p>Define, develop and implement secured archiving.</p> <p>Provision of secure data centre (as a service) </p> <p>Provision of records updates</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(12): monitors compliance of the organisation with the requirements of this Regulation and provides feedback on findings to the accountable manager / head of design organisation to ensure effective implementation of corrective actions;</p> </td> <td valign="top" width="302"> <p>Compliance monitoring (as foreseen by <a href="#_DxCrossRefBm1193569689">IS.D.OR.240</a>) including the execution of independent audits </p> </td> </tr> <tr> <td valign="top" width="302"> <p>(a)(13): protects, without prejudice to applicable incident reporting requirements, the confidentiality of any information that the organisation may have received from other organisations, according to its level of sensitivity.</p> </td> <td valign="top" width="302"> <p>Define, develop and implement solutions to protect the confidentiality of any information.</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(b): In order to continuously meet the requirements referred to in Article 1, the organisation shall implement a continuous improvement process in accordance with point <a href="#_DxCrossRefBm1193569685">IS.D.OR.260</a>.</p> </td> <td valign="top" width="302"> <p>Execute independent effectiveness and maturity assessments.</p> <p>Define, develop and implement the necessary improvement measures.</p> </td> </tr> <tr> <td valign="top" width="302"> <p>(c): The organisation shall document, in accordance with point <a href="#_DxCrossRefBm1193569687">IS.D.OR.250</a>, all key processes, procedures, roles and responsibilities required to comply with point <a href="#_DxCrossRefBm1193569683">IS.D.OR.200</a>(a), and shall establish a process for amending this documentation. Changes to those processes, procedures, roles and responsibilities shall be managed in accordance with point <a href="#_DxCrossRefBm1193569686">IS.D.OR.255</a>.</p> </td> <td valign="top" width="302"> <p>Production of documentation to detail all key processes, procedures, roles and responsibilities required to comply with point <a href="#_DxCrossRefBm1193569683">IS.D.OR.200</a>(a) (e.g. information security policies, general description of the staff, procedures to specify compliance).</p> <p>Define, develop and implement processes for approving amendments and changes.</p> </td> </tr> </table>
##### GM3 IS.D.OR.235 Contracting of information security management activities *ED Decision 2023/009/R* **EXAMPLES** The following Table 1 provides some examples of information security management activities that may be contracted in relation to the provisions referred to as in [IS.D.OR.200](#_DxCrossRefBm1749084427). **Table 1: Examples of information security management activities that may be contracted** <table cellpadding="7" cellspacing="0"> <col/> <col/> <thead> <tr valign="top"> <td bgcolor="#bfbfbf"><p align="center"> <b><u><a href="#_DxCrossRefBm1749084427">IS.D.OR.200</a></u> points related to activities</b></p> </td> <td bgcolor="#bfbfbf"><p align="center"> <b>Example of contracted activity</b></p> </td> </tr> </thead> <tbody> <tr valign="top"> <td><p> (a)(1): establishes a policy on information security setting out the overall principles of the organisation with regard to the potential impact of information security risks on aviation safety;</p> </td> <td><p> Information security policy drafting and consultancy</p> </td> </tr> <tr valign="top"> <td><p> (a)(2): identifies and reviews information security risks in accordance with point <u><a href="#_DxCrossRefBm1749084438">IS.D.OR.205</a></u>;</p> </td> <td><p> Identify activities, facilities and resources.</p> <p> Identify interfaces with other organisations which could be exposed to information security risks.</p> <p>Perform risk analysis or part of it, e.g. identify and classify information security risks.</p> </td> </tr> <tr valign="top"> <td><p> (a)(3) defines and implements information security risk treatment measures in accordance with point <u><a href="#_DxCrossRefBm1749084437">IS.D.OR.210</a></u>;</p> </td> <td><p> Define, develop and implement measures.</p> <p> Verify the initial and the continued effectiveness of the implemented measures (e.g. red-team/blue-team exercises, penetration testing, vulnerability scanning, etc.).</p> <p>Communicate to the involved stakeholders the outcome of the risk assessment and their responsibilities as part of the risk treatment process.</p> </td> </tr> <tr valign="top"> <td><p> (a)(4): implements an information security internal reporting scheme in accordance with point <u><a href="#_DxCrossRefBm1749084436">IS.D.OR.215</a></u>;</p> </td> <td><p> Define, develop and implement an internal reporting scheme to enable the collection and evaluation of information security events and vulnerabilities of equipment, processes and services.</p> </td> </tr> <tr valign="top"> <td><p> (a)(5): defines and implements, in accordance with point <u><a href="#_DxCrossRefBm1749084435">IS.D.OR.220</a></u>, the measures required to detect information security events, identifies those events which are considered incidents with a potential impact on aviation safety except as permitted by point <u><a href="#_DxCrossRefBm1749084438">IS.D.OR.205</a></u> (e), and responds to, and recovers from, those information security incidents;</p> </td> <td rowspan="2"><p> Define, develop and implement measures to detect events.</p> <p> Define, develop and implement measures to respond to any event conditions.</p> <p> Define, develop and implement measures aimed at recovering from information security incidents.</p> <p>Implement immediate reaction measures to a information security incident or vulnerability as notified by the competent authority.</p> </td> </tr> <tr valign="top"> <td><p> (a)(6): implements the measures that have been notified by the competent authority as an immediate reaction to an information security incident or vulnerability with an impact on aviation safety;</p> </td> </tr> <tr valign="top"> <td><p> (a)(7): takes appropriate action, in accordance with point <u><a href="#_DxCrossRefBm1749084434">IS.D.OR.225</a></u>, to address findings notified by the competent authority;</p> </td> <td><p> Identify root cause.</p> <p> Define corrective action plan.</p> <p>Provide evidence of the corrective actions implemented to close the finding.</p> </td> </tr> <tr valign="top"> <td><p> (a)(8): implements an external reporting scheme in accordance with point <u><a href="#_DxCrossRefBm1749084243">IS.D.OR.230</a></u> in order to enable the competent authority to take appropriate actions;</p> </td> <td><p> Define, develop and implement an external reporting scheme to enable the communication of the information security incidents and vulnerabilities of equipment, processes and services to the competent authority and when required to the design approval holder or the organisation responsible for the design.</p> </td> </tr> <tr valign="top"> <td><p> (a)(9): complies with the requirements contained in point <u><a href="#_DxCrossRefBm1749084433">IS.D.OR.235</a></u> when contracting any part of the activities described in point <u><a href="#_DxCrossRefBm1749084427">IS.D.OR.200</a></u> to other organisations;</p> </td> <td bgcolor="#a6a6a6"><p> Not applicable</p> </td> </tr> <tr valign="top"> <td><p> (a)(10):complies with the personnel requirements contained in point <u><a href="#_DxCrossRefBm1749084432">IS.D.OR.240</a></u>;</p> </td> <td><p> Activities of the accountable manager / head of design organisation in the frame of the provisions for a ‘common responsible person’ as referred to in <u><a href="#_DxCrossRefBm1749084432">IS.D.OR.240</a></u></p> <p> Compliance monitoring as foreseen by <u><a href="#_DxCrossRefBm1749084432">IS.D.OR.240</a></u></p> <p> Contracted organisation to ensure that sufficient personnel is on duty to perform the activities related to this Regulation</p> <p> Define, develop and deliver adequate training to achieve the competencies required by the staff.</p> <p>Perform pre-employment checks</p> </td> </tr> <tr valign="top"> <td><p> (a)(11):complies with the record-keeping requirements contained in point <u><a href="#_DxCrossRefBm1749084431">IS.D.OR.245</a></u>;</p> </td> <td><p> Define, develop and implement secured archiving.</p> <p> Provision of secure data centre (as a service) </p> <p>Provision of records updates</p> </td> </tr> <tr valign="top"> <td><p> (a)(12):monitors compliance of the organisation with the requirements of this Regulation and provides feedback on findings to the accountable manager / head of design organisation to ensure effective implementation of corrective actions;</p> </td> <td><p> Compliance monitoring (as foreseen by <u><a href="#_DxCrossRefBm1749084432">IS.D.OR.240</a></u>) including the execution of independent audits</p> </td> </tr> <tr valign="top"> <td><p> (a)(13):protects, without prejudice to applicable incident reporting requirements, the confidentiality of any information that the organisation may have received from other organisations, according to its level of sensitivity.</p> </td> <td><p> Define, develop and implement solutions to protect the confidentiality of any information.</p> </td> </tr> <tr valign="top"> <td><p> (b): In order to continuously meet the requirements referred to in Article 1, the organisation shall implement a continuous improvement process in accordance with point <u><a href="#_DxCrossRefBm1749084430">IS.D.OR.260</a></u>.</p> </td> <td><p> Execute independent effectiveness and maturity assessments.</p> <p>Define, develop and implement the necessary improvement measures.</p> </td> </tr> <tr valign="top"> <td><p> (c): The organisation shall document, in accordance with point <u><a href="#_DxCrossRefBm1749084429">IS.D.OR.250</a></u>, all key processes, procedures, roles and responsibilities required to comply with point <u><a href="#_DxCrossRefBm1749084427">IS.D.OR.200</a></u>(a), and shall establish a process for amending this documentation. Changes to those processes, procedures, roles and responsibilities shall be managed in accordance with point <u><a href="#_DxCrossRefBm1749084428">IS.D.OR.255</a></u>.</p> </td> <td><p> Production of documentation to detail all key processes, procedures, roles and responsibilities required to comply with point <u><a href="#_DxCrossRefBm1749084427">IS.D.OR.200</a></u>(a) (e.g. information security policies, general description of the staff, procedures to specify compliance).</p> <p>Define, develop and implement processes for approving amendments and changes.</p> </td> </tr> </tbody> </table>