Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.AR.200(d) Information security management system (ISMS)
Available versions for ERULES-1963177438-21701
ED Decision 2023/010/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.AR.200(d) Information security management system (ISMS) ED Decision 2023/010/R PROPORTIONALITY IN ISMS IMPLEMENTATION When implementing the processes and procedures, as well as establishing the roles and responsibilities required under point [IS.AR.200](#_DxCrossRefBm1193569457)(d), the competent authority should primarily consider the risks that it may be posing to other organisations, as well as its own risk exposure. Other aspects that may be relevant include the authority’s needs and objectives, information security requirements, its own processes, and the size, complexity and structure of the authority, all of which may change over time. INTEGRATION OF ISMS UNDER THIS REGULATION WITH EXISTING MANAGEMENT SYSTEMS A competent authority may take advantage of existing management systems when implementing an ISMS by integrating it with those existing systems. By integrating the ISMS with existing management systems, the competent authority may reduce the effort and costs required to implement and maintain the ISMS, while also ensuring consistency and alignment with the authority’s overall management approach. Below is a non-exhaustive list of potential synergies that can be exploited when integrating the ISMS with an existing management system: — Leverage existing policies and procedures: an authority may use its existing policies and procedures as a foundation for its ISMS. This may help to ensure consistency and minimise the need for additional documentation. — Align the ISMS with other management systems: an authority may align the ISMS with other management systems, such as safety management systems (SMSs), to ensure that the ISMS is consistent with the authority’s overall management approach. — Use existing risk management processes: an authority may use their existing risk management processes to identify and assess the information security risks potentially leading to aviation safety risks. — Reuse existing controls: an authority may reuse existing controls, such as access controls or incident management process, to implement the information security controls required by the ISMS. — Continuous improvement process: an authority may use the continuous improvement process of existing management systems to improve the ISMS over time.
##### GM1 IS.AR.200(d) Information security management system (ISMS) *ED Decision 2023/010/R* **PROPORTIONALITY IN ISMS IMPLEMENTATION** When implementing the processes and procedures, as well as establishing the roles and responsibilities required under point [IS.AR.200](#_DxCrossRefBm1749084191)(d), the competent authority should primarily consider the risks that it may be posing to other organisations, as well as its own risk exposure. Other aspects that may be relevant include the authority’s needs and objectives, information security requirements, its own processes, and the size, complexity and structure of the authority, all of which may change over time. **INTEGRATION OF ISMS UNDER THIS REGULATION WITH EXISTING MANAGEMENT SYSTEMS** A competent authority may take advantage of existing management systems when implementing an ISMS by integrating it with those existing systems. By integrating the ISMS with existing management systems, the competent authority may reduce the effort and costs required to implement and maintain the ISMS, while also ensuring consistency and alignment with the authority’s overall management approach. Below is a non-exhaustive list of potential synergies that can be exploited when integrating the ISMS with an existing management system: — Leverage existing policies and procedures: an authority may use its existing policies and procedures as a foundation for its ISMS. This may help to ensure consistency and minimise the need for additional documentation. — Align the ISMS with other management systems: an authority may align the ISMS with other management systems, such as safety management systems (SMSs), to ensure that the ISMS is consistent with the authority’s overall management approach. — Use existing risk management processes: an authority may use their existing risk management processes to identify and assess the information security risks potentially leading to aviation safety risks. — Reuse existing controls: an authority may reuse existing controls, such as access controls or incident management process, to implement the information security controls required by the ISMS. — Continuous improvement process: an authority may use the continuous improvement process of existing management systems to improve the ISMS over time.