Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.235(a) Contracting of information security management activities
Available versions for ERULES-1963177438-21644
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.235(a) Contracting of information security management activities ED Decision 2023/009/R (a) OVERSIGHT OF THE CONTRACTED ORGANISATION In order to exercise oversight of the contracted organisation, the organisation under Part-IS should have: (1) a process to ensure compliance with the provisions regarding contracted activities contained in this Regulation; (2) a structured process to follow the expected execution of the contract that includes: (i) definition and agreement of the scope of the activities; (ii) definition of the roles and responsibilities of the parties (i.e. contracting and contracted organisation). (iii) definition and review of key performance indicators; (iv) reaction to deviation from contractual obligations; (v) performance of compliance audits, according to the predefined scope and objectives, with the aim of evaluating operational and associated assurance activities. (vi) provision of feedback on the result of the compliance audits both within the organisation and to the contracted organisation, and response to findings. The feedback on the outcome of the compliance audits within the contracting organisation should reach the accountable manager or, in the case of design organisations, the head of the design organisation, or delegated person(s) to ensure proper monitoring of the response to findings (i.e. implementation of corrective actions) or, if deemed necessary, termination of the contract. Note: The right of the organisation to conduct compliance audits of the contracted organisation should be included in the contract between the parties. (b) MANAGEMENT OF THE RISKS ASSOCIATED WITH THE CONTRACTED ACTIVITIES In order to properly manage the risks associated with the contracted activities, the organisation should meet the following criteria: (1) A prior assessment of the suppliers is conducted before outsourcing any information security management activities. The assessment should evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the activities to be contracted. (2) There is an assessment of the risks associated with the provision of the contracted activities that has been agreed between the organisation under Part-IS and the contracted organisation. (3) The organisation establishes and maintains appropriate information security communication channels with the contracted organisation.
##### AMC1 IS.D.OR.235(a) Contracting of information security management activities *ED Decision 2023/009/R* **(a) OVERSIGHT OF THE CONTRACTED ORGANISATION** In order to exercise oversight of the contracted organisation, the organisation under Part-IS should have: (1) a process to ensure compliance with the provisions regarding contracted activities contained in this Regulation; (2) a structured process to follow the expected execution of the contract that includes: (i) definition and agreement of the scope of the activities; (ii) definition of the roles and responsibilities of the parties (i.e. contracting and contracted organisation). (iii) definition and review of key performance indicators; (iv) reaction to deviation from contractual obligations; (v) performance of compliance audits, according to the predefined scope and objectives, with the aim of evaluating operational and associated assurance activities. (vi) provision of feedback on the result of the compliance audits both within the organisation and to the contracted organisation, and response to findings. The feedback on the outcome of the compliance audits within the contracting organisation should reach the accountable manager or, in the case of design organisations, the head of the design organisation, or delegated person(s) to ensure proper monitoring of the response to findings (i.e. implementation of corrective actions) or, if deemed necessary, termination of the contract. Note: The right of the organisation to conduct compliance audits of the contracted organisation should be included in the contract between the parties. **(b) MANAGEMENT OF THE RISKS ASSOCIATED WITH THE CONTRACTED ACTIVITIES** In order to properly manage the risks associated with the contracted activities, the organisation should meet the following criteria: (1) A prior assessment of the suppliers is conducted before outsourcing any information security management activities. The assessment should evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the activities to be contracted. (2) There is an assessment of the risks associated with the provision of the contracted activities that has been agreed between the organisation under Part-IS and the contracted organisation. (3) The organisation establishes and maintains appropriate information security communication channels with the contracted organisation.