Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.255 Changes to the information security management system
Available versions for ERULES-1963177438-21642
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.255 Changes to the information security management system ED Decision 2023/009/R Point [IS.D.OR.255](#_DxCrossRefBm1193569686) is structured as follows: Point (a) introduces the possibility for the organisation to agree with the competent authority that changes to the ISMS can be implemented without prior approval as long as these changes are covered in a change procedure. Point (b) introduces an obligation of prior approval (by the competent authority) for changes not covered by the procedure mentioned above, and indicates how those changes should be handled. The organisation should consider the establishment of a procedure in order to manage and notify changes to the competent authority as provided for under [IS.D.OR.255](#_DxCrossRefBm1193569686)(a). In case of lack of any approved procedure, the organisation will have, for any change, to apply for and obtain an approval as required under [IS.D.OR.255](#_DxCrossRefBm1193569686)(b). In any case, all changes should be notified to the competent authority upon implementation.
##### GM1 IS.D.OR.255 Changes to the information security management system *ED Decision 2023/009/R* Point [IS.D.OR.255](#_DxCrossRefBm1749084428) is structured as follows: Point (a) introduces the possibility for the organisation to agree with the competent authority that changes to the ISMS can be implemented without prior approval as long as these changes are covered in a change procedure. Point (b) introduces an obligation of prior approval (by the competent authority) for changes not covered by the procedure mentioned above, and indicates how those changes should be handled. The organisation should consider the establishment of a procedure in order to manage and notify changes to the competent authority as provided for under [IS.D.OR.255](#_DxCrossRefBm1749084428)(a). In case of lack of any approved procedure, the organisation will have, for any change, to apply for and obtain an approval as required under [IS.D.OR.255](#_DxCrossRefBm1749084428)(b). In any case, all changes should be notified to the competent authority upon implementation.