Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.I.OR.200(a)(1) Information security management system (ISMS)
Available versions for ERULES-1963177438-21757
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.I.OR.200(a)(1) Information security management system (ISMS) ED Decision 2023/009/R The organisation should define and document the scope of the ISMS, by determining activities, processes, supporting systems, and identifying those which may have an impact on aviation safety. The information security policy should be endorsed by the accountable manager and reviewed at planned intervals or if significant changes occur. Moreover, the policy should cover at least the following aspects with a potential impact on aviation safety by: (a) committing to comply with applicable legislation, consider relevant standards and best practices; (b) setting objectives and performance measures for managing information security; (c) defining general principles, activities, processes for the organisation to appropriately secure information and communication technology systems and data; (d) committing to apply ISMS requirements into the processes of the organisation; (e) committing to continually improve towards higher levels of information security process maturity as per [IS.I.OR.260](#_DxCrossRefBm1193569542); (f) committing to satisfy applicable requirements regarding information security and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation; (g) assigning information security as one of the essential responsibilities for all managers; (h) committing to promote the information security policy through training or awareness sessions within the organisation to all personnel on a regular basis or upon modifications; (i) encouraging the implementation of a ‘just-culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents; (j) committing to communicate the information security policy to all relevant parties, as appropriate. Note: A significant change is a notable alteration or modification that has a meaningful impact on the organisation’s operations, such as a structural change within the organisation due to reorganisations, a change in the business processes (e.g. working from home, use of personal devices), a technological evolution (e.g. distributed computing resources, artificial intelligence/machine learning) or an evolution in the threat landscape.
##### AMC1 IS.I.OR.200(a)(1) Information security management system (ISMS) *ED Decision 2023/009/R* The organisation should define and document the scope of the ISMS, by determining activities, processes, supporting systems, and identifying those which may have an impact on aviation safety. The information security policy should be endorsed by the accountable manager and reviewed at planned intervals or if significant changes occur. Moreover, the policy should cover at least the following aspects with a potential impact on aviation safety by: (a) committing to comply with applicable legislation, consider relevant standards and best practices; (b) setting objectives and performance measures for managing information security; (c) defining general principles, activities, processes for the organisation to appropriately secure information and communication technology systems and data; (d) committing to apply ISMS requirements into the processes of the organisation; (e) committing to continually improve towards higher levels of information security process maturity as per [IS.I.OR.260](#_DxCrossRefBm1749084280); (f) committing to satisfy applicable requirements regarding information security and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation; (g) assigning information security as one of the essential responsibilities for all managers; (h) committing to promote the information security policy through training or awareness sessions within the organisation to all personnel on a regular basis or upon modifications; (i) encouraging the implementation of a ‘just-culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents; (j) committing to communicate the information security policy to all relevant parties, as appropriate. Note: A significant change is a notable alteration or modification that has a meaningful impact on the organisation’s operations, such as a structural change within the organisation due to reorganisations, a change in the business processes (e.g. working from home, use of personal devices), a technological evolution (e.g. distributed computing resources, artificial intelligence/machine learning) or an evolution in the threat landscape.