Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.260(a) Continuous improvement
Available versions for ERULES-1963177438-21657
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.260(a) Continuous improvement ED Decision 2023/009/R (a) As general guidance, the elements of the ISMS that should be monitored, measured and evaluated should be, as a minimum: (1) the risk assessment and treatment process (including risks at the interfaces with other organisations); (2) the management of non-conformities and corrective actions; (3) the incident and vulnerability management; (4) the personnel competence management. (b) Existing maturity models for ISMS maturity evaluation As general guidance, for the definition or the adoption of a maturity model (MM), the following existing models may be considered: — Cybersecurity Capability Maturity Model (C2M2), version 1.1: this model was published by the US Department of Energy in 2014. It introduces the notion of Maturity Indicator Levels (MIL) ranging from 0 to 3 and addresses not only performance levels but also performance practices (under Approach Objectives and approach progression) as well as assurance practices (under Management Objectives and institutionalization progression). — Systems Security Engineering – Capability Maturity Model (SSE-CMM): published by ISO as ISO 21827 in 2008. It focuses on engineering practices, much less on operational practices that are split in 11 ‘Security Base Practices’, and 11 ‘Project and Organizational Base Practices’. It introduces the notion of five Capability Levels, from ‘Performed Informally’ to ‘Continuously Improving’. — NIST Cybersecurity Framework (NIST CSF), version 1.1: published by NIST in April 2018. Although it is not proposed as a MM, the framework defines four ‘Implementation Tiers’, from ‘Partial’ to ‘Adaptive’, which are a qualitative measure of organisational cybersecurity risk management practices. It focuses on the functionality and repeatability of cybersecurity risk management. — ATM Cybersecurity Maturity Model, edition 1: published in February 2019 by the EUROCONTROL NM for organisations in the ATM domain. Whilst not being designed for wider application, it can be adapted as necessary. It defines five maturity levels, ranging from ‘Non-existent’ to ‘Adaptive’ inspired by the ‘Tier’ terminology from the NIST CSF. In fact, the model is founded on NIST CSF, together with some elements of ISO/IEC 27001. The following Table 1 maps the MM mentioned above to a hypothetical five-level MM. *Table 1: Mapping matrix of an existing MM to a hypothetical five-level MM* <table border="0" cellpadding="0" cellspacing="0" width="558"> <tr> <td width="90"> <p>Mapping to a five-level MM</p> </td> <td width="117"> <p>C2M2</p> </td> <td width="117"> <p>Eurocontrol NM</p> </td> <td width="117"> <p>ISO 21827</p> </td> <td width="117"> <p>NIST CSF 1.1</p> </td> </tr> <tr> <td width="0"> <p>Initial</p> </td> <td width="0"> <p>MIL 0</p> </td> <td width="0"> <p>Non-Existent</p> </td> <td width="0"> <p>Performed Informally</p> </td> <td width="0"> </td> </tr> <tr> <td width="0"> <p>Defined</p> </td> <td width="0"> <p>MIL 1 (Initial)</p> </td> <td width="0"> <p>Partial</p> </td> <td width="0"> <p>Planned & Tracked</p> </td> <td width="0"> <p>Partial</p> </td> </tr> <tr> <td width="0"> <p>Implemented</p> </td> <td width="0"> <p>MIL 2 (Identified)</p> </td> <td width="0"> <p>Defined</p> </td> <td width="0"> <p>Well defined</p> </td> <td width="0"> <p>Risk-Informed</p> </td> </tr> <tr> <td width="0"> <p>Managed</p> </td> <td width="0"> <p>MIL 3 (Managed)</p> </td> <td width="0"> <p>Assured</p> </td> <td width="0"> <p>Quantitatively Controlled</p> </td> <td width="0"> <p>Repeatable</p> </td> </tr> <tr> <td width="0"> <p>Improved</p> </td> <td width="0"> <p>Adaptive</p> </td> <td width="0"> <p>Continuously Improving</p> </td> <td width="0"> <p>Adaptive</p> </td> </tr> </table> No specific maturity level is required. However, if and when compliance is achieved, organisations will determine which requirements of which models have already been met (mandatory) and can opt to reach a level that is beneficial to the organisation (voluntary). In the longer term, achieving higher maturity levels may increase the confidence of oversight authorities, which can have an impact upon the level of oversight activities regarding such organisation.
##### GM1 IS.D.OR.260(a) Continuous improvement *ED Decision 2023/009/R* (a) As general guidance, the elements of the ISMS that should be monitored, measured and evaluated should be, as a minimum: (1) the risk assessment and treatment process (including risks at the interfaces with other organisations); (2) the management of non-conformities and corrective actions; (3) the incident and vulnerability management; (4) the personnel competence management. (b) Existing maturity models for ISMS maturity evaluation As general guidance, for the definition or the adoption of a maturity model (MM), the following existing models may be considered: — Cybersecurity Capability Maturity Model (C2M2), version 1.1: this model was published by the US Department of Energy in 2014. It introduces the notion of Maturity Indicator Levels (MIL) ranging from 0 to 3 and addresses not only performance levels but also performance practices (under Approach Objectives and approach progression) as well as assurance practices (under Management Objectives and institutionalization progression). — Systems Security Engineering – Capability Maturity Model (SSE-CMM): published by ISO as ISO 21827 in 2008. It focuses on engineering practices, much less on operational practices that are split in 11 ‘Security Base Practices’, and 11 ‘Project and Organizational Base Practices’. It introduces the notion of five Capability Levels, from ‘Performed Informally’ to ‘Continuously Improving’. — NIST Cybersecurity Framework (NIST CSF), version 1.1: published by NIST in April 2018. Although it is not proposed as a MM, the framework defines four ‘Implementation Tiers’, from ‘Partial’ to ‘Adaptive’, which are a qualitative measure of organisational cybersecurity risk management practices. It focuses on the functionality and repeatability of cybersecurity risk management. — ATM Cybersecurity Maturity Model, edition 1: published in February 2019 by the EUROCONTROL NM for organisations in the ATM domain. Whilst not being designed for wider application, it can be adapted as necessary. It defines five maturity levels, ranging from ‘Non-existent’ to ‘Adaptive’ inspired by the ‘Tier’ terminology from the NIST CSF. In fact, the model is founded on NIST CSF, together with some elements of ISO/IEC 27001. The following Table 1 maps the MM mentioned above to a hypothetical five-level MM. **Table 1: Mapping matrix of an existing MM to a hypothetical five-level MM** <table cellpadding="7" cellspacing="0"> <colgroup> <col/> </colgroup> <colgroup> <col/> <col/> <col/> <col/> </colgroup> <tbody> <tr> <td bgcolor="#bfbfbf"><p align="left"> <b>Mapping to a five-level MM</b></p> </td> <td bgcolor="#bfbfbf"><p align="left"> <b>C2M2</b></p> </td> <td bgcolor="#bfbfbf"><p align="left"> <b>Eurocontrol NM</b></p> </td> <td bgcolor="#bfbfbf"><p align="left"> <b>ISO 21827</b></p> </td> <td bgcolor="#bfbfbf"><p align="left"> <b>NIST CSF 1.1</b></p> </td> </tr> </tbody> <tbody> <tr> <td bgcolor="#bfbfbf"><p align="left"> <b>Initial</b></p> </td> <td><p align="left"> MIL 0</p> </td> <td><p align="left"> Non-Existent</p> </td> <td><p align="left"> Performed Informally</p> </td> <td bgcolor="#d9d9d9"><p align="left"> <br/> </p> </td> </tr> <tr> <td bgcolor="#bfbfbf"><p align="left"> <b>Defined</b></p> </td> <td><p align="left"> MIL 1 (Initial)</p> </td> <td><p align="left"> Partial</p> </td> <td><p align="left"> Planned & Tracked</p> </td> <td><p align="left"> Partial</p> </td> </tr> <tr> <td bgcolor="#bfbfbf"><p align="left"> <b>Implemented</b></p> </td> <td><p align="left"> MIL 2 (Identified)</p> </td> <td><p align="left"> Defined</p> </td> <td><p align="left"> Well defined</p> </td> <td><p align="left"> Risk-Informed</p> </td> </tr> <tr> <td bgcolor="#bfbfbf"><p align="left"> <b>Managed</b></p> </td> <td><p align="left"> MIL 3 (Managed)</p> </td> <td><p align="left"> Assured</p> </td> <td><p align="left"> Quantitatively Controlled</p> </td> <td><p align="left"> Repeatable</p> </td> </tr> <tr> <td bgcolor="#bfbfbf"><p align="left"> <b>Improved</b></p> </td> <td bgcolor="#d9d9d9"><p align="left"> <br/> </p> </td> <td><p align="left"> Adaptive</p> </td> <td><p align="left"> Continuously Improving</p> </td> <td><p align="left"> Adaptive</p> </td> </tr> </tbody> </table> No specific maturity level is required. However, if and when compliance is achieved, organisations will determine which requirements of which models have already been met (mandatory) and can opt to reach a level that is beneficial to the organisation (voluntary). In the longer term, achieving higher maturity levels may increase the confidence of oversight authorities, which can have an impact upon the level of oversight activities regarding such organisation.