Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.I.OR.200(c) Information security management system (ISMS)
Available versions for ERULES-1963177438-21777
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.I.OR.200(c) Information security management system (ISMS) ED Decision 2023/009/R The amount of information that should be documented to maintain compliance with the objectives of this Regulation may vary between organisations due to various factors, such as size and complexity, or the need for harmonisation with other management processes already in place. As general guidance, taking into account the documents required to comply with point [IS.I.OR.200](#_DxCrossRefBm1193569541)(a), the record-keeping requirements referred to in [IS.I.OR.245](#_DxCrossRefBm1193569545) and the information security management manual requirements referred to in [IS.I.OR.250](#_DxCrossRefBm1193569544), the following is a non-exhaustive list of information that should be documented: (a) information security policy that should include the organisation’s information security objectives — see [IS.I.OR.200](#_DxCrossRefBm1193569541)(a)(1); (b) responsibilities and accountabilities for roles relevant to information security — see [IS.I.OR.250](#_DxCrossRefBm1193569544)(a)(2), (3), (6) and (7) and the personnel requirements referred to in points [IS.I.OR.240](#_DxCrossRefBm1193569546)(a), (b), (c), (d) and (f) and the related AMC and GM; (c) scope of the ISMS and the interfaces with, and dependencies on, other parties — see [IS.I.OR.200](#_DxCrossRefBm1193569541)(a)(2) and the information security requirements referred to in points [IS.I.OR.205](#_DxCrossRefBm1193569493)(a) and (b); (d) information security risk management process — see the information security requirements referred to in points [IS.I.OR.205](#_DxCrossRefBm1193569493) and [IS.I.OR.210](#_DxCrossRefBm1193569551); (e) archive of the risks identified in the information security risk assessment along with the associated risk treatment measures (often referred to as ‘risk register’ or ‘risk ledger’) — see [IS.I.OR.245](#_DxCrossRefBm1193569545); (f) evidence of the competencies necessary for the personnel performing the activities required under this Regulation — see [IS.I.OR.240](#_DxCrossRefBm1193569546)(g) and the related AMC and GM; (g) evidence of the current competencies of the personnel performing the activities required under this Regulation — see [IS.I.OR.245](#_DxCrossRefBm1193569545)(b)(1); (h) (key) performance indicators derived from evidence of the monitoring and measurement of the ISMS processes.
##### GM1 IS.I.OR.200(c) Information security management system (ISMS) *ED Decision 2023/009/R* The amount of information that should be documented to maintain compliance with the objectives of this Regulation may vary between organisations due to various factors, such as size and complexity, or the need for harmonisation with other management processes already in place. As general guidance, taking into account the documents required to comply with point [IS.I.OR.200](#_DxCrossRefBm1749084277)(a), the record-keeping requirements referred to in [IS.I.OR.245](#_DxCrossRefBm1749084281) and the information security management manual requirements referred to in [IS.I.OR.250](#_DxCrossRefBm1749084279), the following is a non-exhaustive list of information that should be documented: (a) information security policy that should include the organisation’s information security objectives — see [IS.I.OR.200](#_DxCrossRefBm1749084277)(a)(1); (b) responsibilities and accountabilities for roles relevant to information security — see [IS.I.OR.250](#_DxCrossRefBm1749084279)(a)(2), (3), (6) and (7) and the personnel requirements referred to in points [IS.I.OR.240](#_DxCrossRefBm1749084282)(a), (b), (c), (d) and (f) and the related AMC and GM; (c) scope of the ISMS and the interfaces with, and dependencies on, other parties — see [IS.I.OR.200](#_DxCrossRefBm1749084277)(a)(2) and the information security requirements referred to in points [IS.I.OR.205](#_DxCrossRefBm1749084227)(a) and (b); (d) information security risk management process — see the information security requirements referred to in points [IS.I.OR.205](#_DxCrossRefBm1749084227) and [IS.I.OR.210](#_DxCrossRefBm1749084287); (e) archive of the risks identified in the information security risk assessment along with the associated risk treatment measures (often referred to as ‘risk register’ or ‘risk ledger’) — see [IS.I.OR.245](#_DxCrossRefBm1749084281); (f) evidence of the competencies necessary for the personnel performing the activities required under this Regulation — see [IS.I.OR.240](#_DxCrossRefBm1749084282)(g) and the related AMC and GM; (g) evidence of the current competencies of the personnel performing the activities required under this Regulation — see [IS.I.OR.245](#_DxCrossRefBm1749084281)(b)(1); (h) (key) performance indicators derived from evidence of the monitoring and measurement of the ISMS processes.