Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.260(a) Continuous improvement
Available versions for ERULES-1963177438-21654
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.260(a) Continuous improvement ED Decision 2023/009/R (a) ISMS EFFECTIVENESS EVALUATION When complying with [IS.D.OR.260](#_DxCrossRefBm1193569685)(a), the organisation should have a process in place to monitor, measure, evaluate and review the effectiveness of its ISMS that defines: (1) who monitors, measures, analyses and evaluates the results and takes accountable decisions; (2) when the above steps should be performed; (3) which methods for monitoring, measurement, analysis and evaluation are applied to ensure comparable and reproducible results. The calendar basis of the assessments should be commensurate with the maximum level of risk established under [IS.D.OR.205](#_DxCrossRefBm1193569684). The process to monitor, measure, evaluate and review the effectiveness of the organisation’s ISMS referred to under [AMC1 IS.D.OR.260(a)](#_DxCrossRefBm1193569797) should include as a minimum: (1) the gathering and retention of metrics of the activities, and additional information that could be useful for monitoring purposes; (2) the analysis of the metrics in order to identify trends and deviations from predefined performance targets. (b) ISMS MATURITY ASSESSMENT The organisation should assess the maturity of its ISMS using a suitable maturity model in order to identify areas for improvement to the ISMS. To do so, the organisation should: (1) define or adopt a maturity model which represents a set of important and relevant processes and capabilities that are expected to be implemented and maintained; (2) for each assessed process or capability, ensure that the model defines criteria against which specific aspects, characteristics and effectiveness should be assessed and evaluated when determining a maturity level; (3) define for each assessed process or capability its desired target maturity level. (c) For each assessed information security process or capability contained in the maturity model, the organisation should: (1) evaluate and justify the current maturity level; (2) identify any area for improvement it should make to reach the targeted maturity level; (3) collect and record the evidence regarding strengths and weaknesses of the implemented ISMS and its evaluated maturity.
##### AMC1 IS.D.OR.260(a) Continuous improvement *ED Decision 2023/009/R* (a) **ISMS EFFECTIVENESS EVALUATION** When complying with [IS.D.OR.260](#_DxCrossRefBm1749084430)(a), the organisation should have a process in place to monitor, measure, evaluate and review the effectiveness of its ISMS that defines: (1) who monitors, measures, analyses and evaluates the results and takes accountable decisions; (2) when the above steps should be performed; (3) which methods for monitoring, measurement, analysis and evaluation are applied to ensure comparable and reproducible results. The calendar basis of the assessments should be commensurate with the maximum level of risk established under [IS.D.OR.205](#_DxCrossRefBm1749084438). The process to monitor, measure, evaluate and review the effectiveness of the organisation’s ISMS referred to under AMC1 IS.D.OR.260(a) should include as a minimum: (1) the gathering and retention of metrics of the activities, and additional information that could be useful for monitoring purposes; (2) the analysis of the metrics in order to identify trends and deviations from predefined performance targets. (b) **ISMS MATURITY ASSESSMENT** The organisation should assess the maturity of its ISMS using a suitable maturity model in order to identify areas for improvement to the ISMS. To do so, the organisation should: (1) define or adopt a maturity model which represents a set of important and relevant processes and capabilities that are expected to be implemented and maintained; (2) for each assessed process or capability, ensure that the model defines criteria against which specific aspects, characteristics and effectiveness should be assessed and evaluated when determining a maturity level; (3) define for each assessed process or capability its desired target maturity level. (c) For each assessed information security process or capability contained in the maturity model, the organisation should: (1) evaluate and justify the current maturity level; (2) identify any area for improvement it should make to reach the targeted maturity level; (3) collect and record the evidence regarding strengths and weaknesses of the implemented ISMS and its evaluated maturity.