Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.AR.230(a)(1)(iv)&(a)(4) Record-keeping
Available versions for ERULES-1963177438-21720
ED Decision 2023/010/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.AR.230(a)(1)(iv)&(a)(4) Record-keeping ED Decision 2023/010/R The objective of the requirement (a)(1)(iv) is to ensure detection of possible indication of information security incidents or vulnerabilities which are not obvious by normal operation (e.g. previously unknown situations), while the objective of the requirement under (a)(4) is to allow the necessary flexibility to control the volume of the stored information security events. Records of information security events include those events identified within the scope of the detection activities under [IS.AR.215](#_DxCrossRefBm1193569462)(a), as well as other information security data produced by assets that have been identified under [IS.AR.205](#_DxCrossRefBm1193569464). A data retention policy clarifies what information should be stored or archived and for how long. Some guidance about data retention can be found in EUROCAE ED-206, Chapter 2.6. Once a data set completes its retention period, it can be deleted or moved as permanent historical data to a secondary or tertiary storage.
##### GM1 IS.AR.230(a)(1)(iv)&(a)(4) Record-keeping *ED Decision 2023/010/R* The objective of the requirement (a)(1)(iv) is to ensure detection of possible indication of information security incidents or vulnerabilities which are not obvious by normal operation (e.g. previously unknown situations), while the objective of the requirement under (a)(4) is to allow the necessary flexibility to control the volume of the stored information security events. Records of information security events include those events identified within the scope of the detection activities under [IS.AR.215](#_DxCrossRefBm1749084196)(a), as well as other information security data produced by assets that have been identified under [IS.AR.205](#_DxCrossRefBm1749084198). A data retention policy clarifies what information should be stored or archived and for how long. Some guidance about data retention can be found in EUROCAE ED-206, Chapter 2.6. Once a data set completes its retention period, it can be deleted or moved as permanent historical data to a secondary or tertiary storage.