Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.D.OR.240(b) Personnel requirements
Available versions for ERULES-1963177438-21672
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.D.OR.240(b) Personnel requirements ED Decision 2023/009/R APPOINTMENT OF A PERSON OR GROUP OF PERSONS The person or group of persons appointed under point [IS.D.OR.240](#_DxCrossRefBm1193569689)(b) with the responsibility to ensure compliance with the requirements of this Regulation should represent the management structure of the organisation. The person or group of persons has direct access to the accountable manager or, in the case of design organisations, to the head of the design organisation (or the common responsible person, if appointed) to provide guidance, direction and support for the planning, implementation and operation of the process and standards to comply with the Regulation. They should have direct access to keep the accountable manager or, in the case of design organisations, the head of the design organisation (or the common responsible person) properly informed on compliance and information security matters (for instance, through meetings organised on a regular basis). Appointments should take into account the possibility that a person may not be able to carry out the organisational tasks assigned to them for a period of time, and thus also identify the necessary deputies. These appointed persons should demonstrate a complete understanding of the requirements of this Regulation, to be able to ensure that the organisation’s processes and standards accurately reflect the applicable requirements. It is their role to ensure that compliance is proactively managed, and that any early warning signs of non-compliance are documented and acted upon. A description of the functions and the responsibilities of the appointed persons and deputies, including their names, should be contained in the ISMM (see point [IS.D.OR.250](#_DxCrossRefBm1193569687)(a)(2)).
##### AMC1 IS.D.OR.240(b) Personnel requirements *ED Decision 2023/009/R* **APPOINTMENT OF A PERSON OR GROUP OF PERSONS** The person or group of persons appointed under point [IS.D.OR.240](#_DxCrossRefBm1749084432)(b) with the responsibility to ensure compliance with the requirements of this Regulation should represent the management structure of the organisation. The person or group of persons has direct access to the accountable manager or, in the case of design organisations, to the head of the design organisation (or the common responsible person, if appointed) to provide guidance, direction and support for the planning, implementation and operation of the process and standards to comply with the Regulation. They should have direct access to keep the accountable manager or, in the case of design organisations, the head of the design organisation (or the common responsible person) properly informed on compliance and information security matters (for instance, through meetings organised on a regular basis). Appointments should take into account the possibility that a person may not be able to carry out the organisational tasks assigned to them for a period of time, and thus also identify the necessary deputies. These appointed persons should demonstrate a complete understanding of the requirements of this Regulation, to be able to ensure that the organisation’s processes and standards accurately reflect the applicable requirements. It is their role to ensure that compliance is proactively managed, and that any early warning signs of non-compliance are documented and acted upon. A description of the functions and the responsibilities of the appointed persons and deputies, including their names, should be contained in the ISMM (see point [IS.D.OR.250](#_DxCrossRefBm1749084429)(a)(2)).