Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.D.OR.210 Information security risk treatment
Available versions for ERULES-1963177438-21662
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
ED Decision 2025/014/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Dec 2025)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.D.OR.210 Information security risk treatment ED Decision 2023/009/R Unacceptable risks identified in accordance with point [IS.D.OR.205](#_DxCrossRefBm1193569684) require a risk treatment process that may lead to the introduction of information security measures, often referred to as information security controls. For each identified risk, the organisation should define the specific risk treatment measures, methods or resources that will be used over the life cycle of each asset to: — manage risk reduction; — monitor and maintain each asset; — update and fulfil activities for configuration management; — manage supply chain; — manage contracted services or service provider. The review of risk treatment measures should include life cycle considerations which are introduced by equipment, procedures and personnel. A risk treatment plan as an outcome of the risk management process should include a prioritisation of risks, the corresponding information on the objectives and means for risk treatment to reach an acceptable level of risk, as well as agreed timelines specifying when responsible personnel should have implemented the risk treatment measures. The timelines for the implementation of a risk treatment measure should be agreed by the personnel responsible for the implementation and should be communicated to and accepted by the accountable manager or, in the case of design organisations, by the head of the design organisation, of the organisation or delegated person(s). Any subsequent implementation delay, together with its cause, reason, rationale or necessity, should be documented in the risk treatment plan, for risks that may lead to an unsafe condition. The updated risk treatment should be communicated to the competent authority in case the materialisation of risk would lead to an unsafe condition. The delay is also subject to the acceptance by the accountable manager of the organisation, or by the head of the design organisation, or delegated person(s). This person may condition such acceptance on the implementation or availability of compensating controls or reactive measures to monitor, early detect and timely respond to the materialisation of the risk in treatment. In order to timely respond, the incident response team may be informed to trigger their preparedness. The risk treatment plan can act as a means of communication with the competent authority to demonstrate effective treatment of unacceptable risks. Similarly, this plan can be utilised to communicate to interfacing organisations how shared risks are controlled. In accordance with [IS.D.OR.205](#_DxCrossRefBm1193569684)(d), a regular or conditional review of the risk assessment is necessary, and this includes the review of the risk treatment measures developed under [IS.D.OR.210](#_DxCrossRefBm1193569694)(a) to identify whether they are still effective or they require adaptations. In addition, the organisation should also consider the potential impact on the effectiveness of risk treatment measures where a shared information security risk may arise as a result of the interaction between interfacing entities (see [IS.D.OR.235](#_DxCrossRefBm1193569690) and related AMC).
##### GM1 IS.D.OR.210 Information security risk treatment *ED Decision 2025/014/R* Unacceptable risks identified in accordance with point [IS.D.OR.205](#_DxCrossRefBm1749084438) require a risk treatment process that may lead to the introduction of information security measures, often referred to as information security controls. For each identified risk, the organisation defines the specific risk treatment measures, methods or resources that will be used over the life cycle of each asset to: — manage risk reduction; — monitor and maintain each asset; — update and fulfil activities for configuration management; — manage supply chain; — manage contracted services or service provider. The review of risk treatment measures includes life cycle considerations which are introduced by equipment, procedures and personnel. A risk treatment plan as an outcome of the risk management process includes a prioritisation of risks, the corresponding information on the objectives and means for risk treatment to reach an acceptable level of risk, as well as agreed timelines specifying when responsible personnel should have implemented the risk treatment measures. The timelines for the implementation of a risk treatment measure are subject to agreement by the personnel responsible for the implementation and are communicated to and accepted by the accountable manager or, in the case of design organisations, by the head of the design organisation, of the organisation or delegated person(s). Any subsequent implementation delay, together with its cause, reason, rationale or necessity, is documented in the risk treatment plan, for risks that may lead to an unsafe condition. The delay is also subject to the acceptance by the accountable manager of the organisation, or by the head of the design organisation, or delegated person(s). This person may condition such acceptance on the implementation or availability of compensating controls or reactive measures to monitor, early detect and timely respond to the materialisation of the risk in treatment. In order to timely respond, the incident response team may be informed to trigger their preparedness. The risk treatment plan can act as a means of communication with the competent authority to demonstrate effective treatment of unacceptable risks. Similarly, this plan can be utilised to communicate to interfacing organisations how shared risks are controlled. In accordance with IS.D.OR.205(d), a regular or conditional review of the risk assessment is necessary, and this includes the review of the risk treatment measures developed under [IS.D.OR.210](#_DxCrossRefBm1749084437)(a) to identify whether they are still effective or they require adaptations. In addition, the organisation should also consider the potential impact on the effectiveness of risk treatment measures where a shared information security risk may arise as a result of the interaction between interfacing entities (see [IS.D.OR.235](#_DxCrossRefBm1749084433) and related AMC).