Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.235(a) Contracting of information security management activities
Available versions for ERULES-1963177438-21646
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.235(a) Contracting of information security management activities ED Decision 2023/009/R PRIOR ASSESSMENT The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the organisation, and may therefore be carried out in different ways, such as: (a) in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers; (b) review of the information security certifications granted by external and impartial auditors to the potential suppliers; (c) review of self-assessment questionnaires compiled by the potential suppliers; RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following: (a) identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers; (b) identification of the information security requirements of the organisation that are applicable to the contracted organisation; (c) evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the contracting organisation; (d) assessment of risks that may be introduced by the contracted organisation. This agreed risk assessment should also consider the roles and responsibilities of the contracting and contracted organisation as well as their interfaces.
##### GM1 IS.D.OR.235(a) Contracting of information security management activities *ED Decision 2023/009/R* **PRIOR ASSESSMENT** The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the organisation, and may therefore be carried out in different ways, such as: (a) in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers; (b) review of the information security certifications granted by external and impartial auditors to the potential suppliers; (c) review of self-assessment questionnaires compiled by the potential suppliers; **RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES** The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following: (a) identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers; (b) identification of the information security requirements of the organisation that are applicable to the contracted organisation; (c) evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the contracting organisation; (d) assessment of risks that may be introduced by the contracted organisation. This agreed risk assessment should also consider the roles and responsibilities of the contracting and contracted organisation as well as their interfaces.