Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.205(d) Information security risk assessment
Available versions for ERULES-1963177438-21653
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.205(d) Information security risk assessment ED Decision 2023/009/R The organisation should take into account the following criteria when establishing compliance with the objectives contained in point [IS.D.OR.205](#_DxCrossRefBm1193569684) (d): (a) The risk assessment performed under points [IS.D.OR.205](#_DxCrossRefBm1193569684) (a), (b) and (c) should be reviewed at regular intervals to identify and account for relevant changes. The periodicity at which potential changes have to be evaluated should be determined by the organisation performing the assessment considering the criticality of the assets within the scope of the risk assessment, levels of residual risk of the assets within the scope of the risk assessment and any contractual or regulatory requirements. A higher criticality or level of risk will require more frequent review. (b) The periodicity of risk assessment reviews should be documented by the organisation and include the justification, date of approval and information about the risk owner.
##### AMC1 IS.D.OR.205(d) Information security risk assessment *ED Decision 2023/009/R* The organisation should take into account the following criteria when establishing compliance with the objectives contained in point [IS.D.OR.205](#_DxCrossRefBm1749084438)(d): (a) The risk assessment performed under points IS.D.OR.205(a), (b) and (c) should be reviewed at regular intervals to identify and account for relevant changes. The periodicity at which potential changes have to be evaluated should be determined by the organisation performing the assessment considering the criticality of the assets within the scope of the risk assessment, levels of residual risk of the assets within the scope of the risk assessment and any contractual or regulatory requirements. A higher criticality or level of risk will require more frequent review. (b) The periodicity of risk assessment reviews should be documented by the organisation and include the justification, date of approval and information about the risk owner.