Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.I.OR.200(e) Information security management system (ISMS)
Available versions for ERULES-1963177438-21783
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.I.OR.200(e) Information security management system (ISMS) ED Decision 2023/009/R DEROGATION Organisations should follow the directions provided in [AMC1Â IS.I.OR.205(a)](#_DxCrossRefBm1193569566) and [AMC1Â IS.I.OR.205(b)](#_DxCrossRefBm1193569565) to perform a documented information security risk assessment to seek the approval by the competent authority of a derogation under point [IS.I.OR.200](#_DxCrossRefBm1193569541)(e). In order to justify the grounds for a derogation, the risk assessment is expected to provide explanations for the exclusion of all elements from the scope of the ISMS. It is up to the authority to determine whether this assessment is deemed satisfactory for a derogation to be granted. Organisations that would like to have the risk assessment performed by a third party should consider the requirements of [IS.I.OR.235](#_DxCrossRefBm1193569547) and the related AMC.
##### AMC1 IS.I.OR.200(e) Information security management system (ISMS) *ED Decision 2023/009/R* **DEROGATION** Organisations should follow the directions provided in [AMC1Â IS.I.OR.205(a)](#_DxCrossRefBm1749084303) and [AMC1Â IS.I.OR.205(b)](#_DxCrossRefBm1749084302) to perform a documented information security risk assessment to seek the approval by the competent authority of a derogation under point [IS.I.OR.200](#_DxCrossRefBm1749084277)(e). In order to justify the grounds for a derogation, the risk assessment is expected to provide explanations for the exclusion of all elements from the scope of the ISMS. It is up to the authority to determine whether this assessment is deemed satisfactory for a derogation to be granted. Organisations that would like to have the risk assessment performed by a third party should consider the requirements of [IS.I.OR.235](#_DxCrossRefBm1749084283) and the related AMC.