Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.AR.200(c) Information security management system (ISMS)
Available versions for ERULES-1963177438-21696
ED Decision 2023/010/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.AR.200(c) Information security management system (ISMS) ED Decision 2023/010/R When establishing compliance with the provisions under point [IS.AR.200](#_DxCrossRefBm1193569457)(c), the competent authority should: (a) provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities that will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the person identified in [IS.AR.225](#_DxCrossRefBm1193569459)(a). The competent authority should review the outline of the structure at planned intervals or if significant changes occur (see the Note in [AMC1 IS.AR.200(a)(1)](#_DxCrossRefBm1193569467)); (b) identify and categorise all relevant contracted organisations or qualified entities used to implement the ISMS. The competent authority should define and document procedures for the management of interfaces with all other entities and coordination between the competent authority and other national authorities, contracted organisations or qualified entities; (c) identify and define all key processes and procedures, and internal and external reporting schemes that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The competent authority may adjust existing processes or procedures for compliance; (d) identify and document any other information that will be used to maintain compliance with the objectives of this Regulation; (e) when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy; (f) control the documented information required by the ISMS to ensure that it is: (1) available and suitable for use, where and when it is needed; (2) adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).
##### AMC1 IS.AR.200(c) Information security management system (ISMS) *ED Decision 2023/010/R* When establishing compliance with the provisions under point [IS.AR.200](#_DxCrossRefBm1749084191)(c), the competent authority should: (a) provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities that will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the person identified in [IS.AR.225](#_DxCrossRefBm1749084193)(a). The competent authority should review the outline of the structure at planned intervals or if significant changes occur (see the Note in [AMC1 IS.AR.200(a)(1)](#_DxCrossRefBm1749084201)); (b) identify and categorise all relevant contracted organisations or qualified entities used to implement the ISMS. The competent authority should define and document procedures for the management of interfaces with all other entities and coordination between the competent authority and other national authorities, contracted organisations or qualified entities; (c) identify and define all key processes and procedures, and internal and external reporting schemes that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The competent authority may adjust existing processes or procedures for compliance; (d) identify and document any other information that will be used to maintain compliance with the objectives of this Regulation; (e) when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy; (f) control the documented information required by the ISMS to ensure that it is: (1) available and suitable for use, where and when it is needed; (2) adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).