Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.AR.215 Information security incidents -- detection, response and recovery
Available versions for ERULES-1963177438-21729
ED Decision 2023/010/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.AR.215 Information security incidents ā detection, response and recovery ED Decision 2023/010/R Without prejudice to the definition of āinformation security eventā in [Article 3](#_DxCrossRefBm1193569438) of Regulation (EU) 2023/203, those events that indicate the potential materialisation of unacceptable risks include both occurrences (i.e. anything that causes harm or has the potential to cause harm) and discovery of vulnerabilities. In fact, information security risks are associated with the potential that threats will exploit vulnerabilities, therefore the discovery of an exploitable vulnerability is an information security event. In light of this, in the context of this Regulation: ā detection activities required under [IS.AR.215](#_DxCrossRefBm1193569462)(a) include vulnerability discovery; ā response activities required under [IS.AR.215](#_DxCrossRefBm1193569462)(b) include vulnerability management.
##### GM1 IS.AR.215 Information security incidents ā detection, response and recovery *ED Decision 2023/010/R* Without prejudice to the definition of āinformation security eventā in [Article 3](#_DxCrossRefBm1749084169) of Regulation (EU) 2023/203, those events that indicate the potential materialisation of unacceptable risks include both occurrences (i.e. anything that causes harm or has the potential to cause harm) and discovery of vulnerabilities. In fact, information security risks are associated with the potential that threats will exploit vulnerabilities, therefore the discovery of an exploitable vulnerability is an information security event. In light of this, in the context of this Regulation: ā detection activities required under [IS.AR.215](#_DxCrossRefBm1749084196)(a) include vulnerability discovery; ā response activities required under [IS.AR.215](#_DxCrossRefBm1749084196)(b) include vulnerability management.