Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.I.OR.200(c) Information security management system (ISMS)
Available versions for ERULES-1963177438-21774
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.I.OR.200(c) Information security management system (ISMS) ED Decision 2023/009/R When establishing compliance with the provisions under point [IS.I.OR.200](#_DxCrossRefBm1193569541)(c), the organisation should: (a) provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities. This outline of the structure will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the accountable manager. The organisation should review the outline of the structure at planned intervals or if significant changes occur (see the Note in [AMC1 IS.I.OR.200(a)(1)](#_DxCrossRefBm1193569554)); (b) identify and categorise all relevant contracted organisations used to implement the ISMS. The organisation should define and document procedures for the management of interfaces and coordination between the organisation and other organisations, including contracted organisations; (c) identify and define all key processes and procedures, and internal and external reporting schemes, that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The organisation may adjust existing processes or procedures for compliance; (d) identify and document any other information that will be used to maintain compliance with the objectives of this Regulation; (e) when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy; (f) control the documented information required by the ISMS to ensure that it is: (1) available and suitable for use, where and when it is needed; (2) adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).
##### AMC1 IS.I.OR.200(c) Information security management system (ISMS) *ED Decision 2023/009/R* When establishing compliance with the provisions under point [IS.I.OR.200](#_DxCrossRefBm1749084277)(c), the organisation should: (a) provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities. This outline of the structure will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the accountable manager. The organisation should review the outline of the structure at planned intervals or if significant changes occur (see the Note in [AMC1 IS.I.OR.200(a)(1)](#_DxCrossRefBm1749084290)); (b) identify and categorise all relevant contracted organisations used to implement the ISMS. The organisation should define and document procedures for the management of interfaces and coordination between the organisation and other organisations, including contracted organisations; (c) identify and define all key processes and procedures, and internal and external reporting schemes, that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The organisation may adjust existing processes or procedures for compliance; (d) identify and document any other information that will be used to maintain compliance with the objectives of this Regulation; (e) when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy; (f) control the documented information required by the ISMS to ensure that it is: (1) available and suitable for use, where and when it is needed; (2) adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).