Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM2 IS.D.OR.205(d) Information security risk assessment
Available versions for ERULES-1963177438-21659
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM2 IS.D.OR.205(d) Information security risk assessment ED Decision 2023/009/R The following are examples of changes that should be identified during the risk assessment review as they may trigger an update of the risk assessments: (a) there is a change in the elements subject to information security risks as identified in [IS.D.OR.205](#_DxCrossRefBm1193569684)(a); a change in the elements will include: — additions to, or removals from, the scope of the risk assessment of individual elements; — changes to design or configuration of elements within the scope of the risk assessment that have the potential to alter the risk assessment outcomes; or — changes to values, which would potentially trigger changes to impact levels, of elements within the scope of the risk assessment; (b) there is a change in the interfaces between the organisation and other organisations with which the organisation shares information security risks or relies upon to mitigate information security risks (e.g. supply chains, service providers, cloud providers and customers), as identified in [IS.D.OR.205](#_DxCrossRefBm1193569684)(b), or between the system within the scope of the risk assessment and any other interconnected systems, or in the risks notified to the organisation by other organisations, as identified in [IS.D.OR.205](#_DxCrossRefBm1193569684)(b), or owners or managers of the other systems including: — establishment of new interfaces; — removal of existing interfaces; — changes to existing interfaces that would have the potential to alter the risk assessment outcomes. Note: Some organisational or system interconnections may be with organisations that are not within the scope of this Regulation as defined in Article 2 and therefore are not subject to the requirements of Part-IS. Where this is the case, these organisations should be informed of their responsibility to report such changes as listed above through contractual arrangement and reporting requirements between the affected organisations on a case-by-case basis and where applicable; (c) there is a change in the information or knowledge used for the identification, analysis and classification of risks including: — changes to threats and their values or addition of new threats that have not previously been assessed; — changes to vulnerabilities or addition of new vulnerabilities that have not previously been assessed; — changes in impacts or consequences of assessed threats or vulnerabilities; — changes in aggregation of risks that may result in unacceptable levels of risks; — changes or improvements in the risk management process, risk assessment approach and related activities; — changes or improvements in the treatments of risks; — changes in the criteria used to determine acceptance and treatments of risks; (d) there are lessons learned from the analysis of information security incidents including: — understanding why and how incidents have occurred; and — reviewing all types of incidents including those due to external factors, technical reasons, human errors (inadvertent behaviour). For human intentional acts a distinction can be made between malign and benign actions.
##### GM2 IS.D.OR.205(d) Information security risk assessment *ED Decision 2023/009/R* The following are examples of changes that should be identified during the risk assessment review as they may trigger an update of the risk assessments: (a) there is a change in the elements subject to information security risks as identified in [IS.D.OR.205](#_DxCrossRefBm1749084438)(a); a change in the elements will include: — additions to, or removals from, the scope of the risk assessment of individual elements; — changes to design or configuration of elements within the scope of the risk assessment that have the potential to alter the risk assessment outcomes; or — changes to values, which would potentially trigger changes to impact levels, of elements within the scope of the risk assessment; (b) there is a change in the interfaces between the organisation and other organisations with which the organisation shares information security risks or relies upon to mitigate information security risks (e.g. supply chains, service providers, cloud providers and customers), as identified in [IS.D.OR.205](#_DxCrossRefBm1749084438)(b), or between the system within the scope of the risk assessment and any other interconnected systems, or in the risks notified to the organisation by other organisations, as identified in [IS.D.OR.205](#_DxCrossRefBm1749084438)(b), or owners or managers of the other systems including: — establishment of new interfaces; — removal of existing interfaces; — changes to existing interfaces that would have the potential to alter the risk assessment outcomes. Note: Some organisational or system interconnections may be with organisations that are not within the scope of this Regulation as defined in Article 2 and therefore are not subject to the requirements of Part-IS. Where this is the case, these organisations should be informed of their responsibility to report such changes as listed above through contractual arrangement and reporting requirements between the affected organisations on a case-by-case basis and where applicable; (c) there is a change in the information or knowledge used for the identification, analysis and classification of risks including: — changes to threats and their values or addition of new threats that have not previously been assessed; — changes to vulnerabilities or addition of new vulnerabilities that have not previously been assessed; — changes in impacts or consequences of assessed threats or vulnerabilities; — changes in aggregation of risks that may result in unacceptable levels of risks; — changes or improvements in the risk management process, risk assessment approach and related activities; — changes or improvements in the treatments of risks; — changes in the criteria used to determine acceptance and treatments of risks; (d) there are lessons learned from the analysis of information security incidents including: — understanding why and how incidents have occurred; and — reviewing all types of incidents including those due to external factors, technical reasons, human errors (inadvertent behaviour). For human intentional acts a distinction can be made between malign and benign actions.