Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.I.OR.220(a) Information security incidents -- detection, response and recovery
Available versions for ERULES-1963177438-21754
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.I.OR.220(a) Information security incidents — detection, response and recovery ED Decision 2023/009/R DETECTION When complying with the requirement in [IS.I.OR.220](#_DxCrossRefBm1193569549)(a), the organisation should define and implement a strategy to detect information security incidents which may have a potential impact on safety. This should be done in a way to ensure that at least the detection strategy is able to cover all known information security threats to their assets that may materialise in a safety hazard having unacceptable consequences. DETECTION STRATEGY In order to determine the scope of the event detection, the organisation should: (a) identify a list of threat scenarios from the risks identified under [IS.I.OR.205](#_DxCrossRefBm1193569493); (b) identify, as a minimum, those assets that, if compromised, contribute to the scenario(s) that may materialise in an unsafe condition. For this identification of the assets, the measures introduced under [IS.I.OR.210](#_DxCrossRefBm1193569551) should also be considered. Note: The contribution of an asset to the threat scenario and the materialisation of an unsafe condition should be assessed by considering also the whole functional chain. In some cases, the asset may be at the end of a functional chain and if it is compromised, the effect on safety is direct and may be immediate; conversely, if the asset is far from the end of a functional chain and it is compromised, the effect should propagate and may be delayed.
##### AMC1 IS.I.OR.220(a) Information security incidents — detection, response and recovery *ED Decision 2023/009/R* **DETECTION** When complying with the requirement in [IS.I.OR.220](#_DxCrossRefBm1749084285)(a), the organisation should define and implement a strategy to detect information security incidents which may have a potential impact on safety. This should be done in a way to ensure that at least the detection strategy is able to cover all known information security threats to their assets that may materialise in a safety hazard having unacceptable consequences. **DETECTION STRATEGY** In order to determine the scope of the event detection, the organisation should: (a) identify a list of threat scenarios from the risks identified under [IS.I.OR.205](#_DxCrossRefBm1749084227); (b) identify, as a minimum, those assets that, if compromised, contribute to the scenario(s) that may materialise in an unsafe condition. For this identification of the assets, the measures introduced under [IS.I.OR.210](#_DxCrossRefBm1749084287) should also be considered. Note: The contribution of an asset to the threat scenario and the materialisation of an unsafe condition should be assessed by considering also the whole functional chain. In some cases, the asset may be at the end of a functional chain and if it is compromised, the effect on safety is direct and may be immediate; conversely, if the asset is far from the end of a functional chain and it is compromised, the effect should propagate and may be delayed.