Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.AR.205(d) Information security risk assessment
Available versions for ERULES-1963177438-21721
ED Decision 2023/010/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.AR.205(d) Information security risk assessment ED Decision 2023/010/R The criteria to consider for the frequency of the risk assessment review may be the risk level as well as the criticality and complexity of the assets concerned. The objective of a risk assessment review is to trigger the revaluation of risks, their likelihood and impact in case of relevant changes. One possible way is to have a tiered approach to risk assessment, with a higher-level risk assessment being used for the identification of changes. The higher-level risk assessment could allow the identification of the detailed risks that should be reviewed in a next step. Risk assessments should be subject to regular reviews to: (a) allow for continuous improvement of the quality of risk assessment; (b) ensure efficiency and effectiveness of risk controls and mitigating measures in both their design and operation; (c) review plans and actions for risk treatment; (d) identify any organisational change which may require a review of the priorities as well as of the treatment of risks; (e) maintain an overview of the complete risk picture; and (f) identify any emerging risks. Risk assessment reviews should involve the risk owners, project teams and other stakeholders as applicable. Evidence of risk assessment review should be documented and should include: — evidence of approval of the review by the designated risk owner; and — the rationale behind or basis for the risk owner’s approval of the review. Such evidence may comprise, but is not limited to: — reports which constitute a form of documentation to track information security risks potentially impacting an organisation; — the documentation of the information security risk assessment; — exerts from a business or security risk registry. The periodicity of risk assessment reviews should be documented by the authority in information security manuals, processes or procedures and should align with wider change management activities and management reviews of information security. Further guidance on criteria and frequency of risk assessment review can be found in EUROCAE ED-201A Chapter 4, as well as in EUROCAE ED-205A, Chapter 3.2 (for ATMS/ANS).
##### GM1 IS.AR.205(d) Information security risk assessment *ED Decision 2023/010/R* The criteria to consider for the frequency of the risk assessment review may be the risk level as well as the criticality and complexity of the assets concerned. The objective of a risk assessment review is to trigger the revaluation of risks, their likelihood and impact in case of relevant changes. One possible way is to have a tiered approach to risk assessment, with a higher-level risk assessment being used for the identification of changes. The higher-level risk assessment could allow the identification of the detailed risks that should be reviewed in a next step. Risk assessments should be subject to regular reviews to: (a) allow for continuous improvement of the quality of risk assessment; (b) ensure efficiency and effectiveness of risk controls and mitigating measures in both their design and operation; (c) review plans and actions for risk treatment; (d) identify any organisational change which may require a review of the priorities as well as of the treatment of risks; (e) maintain an overview of the complete risk picture; and (f) identify any emerging risks. Risk assessment reviews should involve the risk owners, project teams and other stakeholders as applicable. Evidence of risk assessment review should be documented and should include: — evidence of approval of the review by the designated risk owner; and — the rationale behind or basis for the risk owner’s approval of the review. Such evidence may comprise, but is not limited to: — reports which constitute a form of documentation to track information security risks potentially impacting an organisation; — the documentation of the information security risk assessment; — exerts from a business or security risk registry. The periodicity of risk assessment reviews should be documented by the authority in information security manuals, processes or procedures and should align with wider change management activities and management reviews of information security. Further guidance on criteria and frequency of risk assessment review can be found in EUROCAE ED-201A Chapter 4, as well as in EUROCAE ED-205A, Chapter 3.2 (for ATMS/ANS).