Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.AR.210(a) Information security risk treatment
Available versions for ERULES-1963177438-21726
ED Decision 2023/010/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.AR.210(a) Information security risk treatment ED Decision 2023/010/R (a) The risk treatment process should reach at least one of the objectives listed under [IS.AR.210](#_DxCrossRefBm1193569463)(a). (b) When establishing compliance with the objectives under points [IS.AR.210](#_DxCrossRefBm1193569463)(a)(1) and [IS.AR.210](#_DxCrossRefBm1193569463)(a)(2), the competent authority should take into account that: (1) the measures developed under these points should be implemented according to a risk treatment plan with defined, risk-based priorities, objectives and agreed timelines and owners; (2) life cycle considerations should be identified and associated to ensure continuous effectiveness of the information security measures including exchange of data with other entities; (3) it should review and update the risk assessment, according to [IS.AR.205](#_DxCrossRefBm1193569464)(d), to evaluate whether the measures developed under these points introduce new unacceptable risks or modify existing risks into a way that they become unacceptable. (c) Risk treatment should be documented and recorded, for example, in a risk registry, even if the risk has been avoided.
##### AMC1 IS.AR.210(a) Information security risk treatment *ED Decision 2023/010/R* (a) The risk treatment process should reach at least one of the objectives listed under [IS.AR.210](#_DxCrossRefBm1749084197)(a). (b) When establishing compliance with the objectives under points [IS.AR.210](#_DxCrossRefBm1749084197)(a)(1) and [IS.AR.210](#_DxCrossRefBm1749084197)(a)(2), the competent authority should take into account that: (1) the measures developed under these points should be implemented according to a risk treatment plan with defined, risk-based priorities, objectives and agreed timelines and owners; (2) life cycle considerations should be identified and associated to ensure continuous effectiveness of the information security measures including exchange of data with other entities; (3) it should review and update the risk assessment, according to [IS.AR.205](#_DxCrossRefBm1749084198)(d), to evaluate whether the measures developed under these points introduce new unacceptable risks or modify existing risks into a way that they become unacceptable. (c) Risk treatment should be documented and recorded, for example, in a risk registry, even if the risk has been avoided.