Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.I.OR.240(i) Personnel requirements
Available versions for ERULES-1963177438-21784
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.I.OR.240(i) Personnel requirements ED Decision 2023/009/R IDENTITY AND TRUSTWORTHINESS (a) Trustworthiness may be established, for example, by: (1) prior to employment, a background check carried out in accordance with the applicable rules of Union and national law. This check may include verification of: (i) education, previous employment and any gaps in the previous years; (ii) absence of criminal record; (iii) any other relevant information or intelligence considered relevant to the suitability of a person to work in the expected role; (2) during employment, monitoring the employee’s commitment and conduct. Note: The absence of criminal record may be verified by means of a certificate issued by the responsible authority in the Member State in accordance with Regulation (EU) 2016/1191. In the case of prospective foreign employees, the above checks may be carried out on the basis of equivalent certificates issued by the country of origin, such as a ‘certificate of good conduct’. (b) Furthermore, the process and criteria to establish personnel’s trustworthiness may have to consider whether: (1) the information systems and data to be accessed have been associated with a high severity of the safety consequences with the risk assessment process under [IS.I.OR.205](#_DxCrossRefBm1193569493); (2) controls or mitigating measures for risk treatment identified during the risk analysis rely on organisational/operational procedures — for instance, correct configuration and administration of information technologies, database operations, information security monitoring, etc. In such cases, the personnel who have administrator rights or unsupervised and unlimited access to the systems and data mentioned in (a)(1), or the personnel who applies the measures under above point (b)(2), may be subject to more stringent criteria. (c) Intelligence and any other relevant information may be gathered by screening and analysing public sources such as social media and websites, within the limits set by relevant national laws and regulations. (d) Some organisations subject to Part-IS may also be subject to Regulation (EU) 2015/1998 that requires successful completion of background checks for personnel in certain roles, as well as a mechanism for the ongoing review of these checks. In such cases the organisation may consider suitable for the establishment of the personnel’s identity and trustworthiness required under Part-IS, in relation to their role, the process and the relevant criteria defined in Regulation (EU) 2015/1998 for standard and enhanced background checks. However, it should be noted that compliance with the provisions for the establishment of identity and trustworthiness under Part-IS does not constitute compliance with the provisions on background checks as defined in Regulation (EU) 2015/1998.
##### GM1 IS.I.OR.240(i) Personnel requirements *ED Decision 2023/009/R* **IDENTITY AND TRUSTWORTHINESS** (a) Trustworthiness may be established, for example, by: (1) prior to employment, a background check carried out in accordance with the applicable rules of Union and national law. This check may include verification of: (i) education, previous employment and any gaps in the previous years; (ii) absence of criminal record; (iii) any other relevant information or intelligence considered relevant to the suitability of a person to work in the expected role; (2) during employment, monitoring the employee’s commitment and conduct. Note: The absence of criminal record may be verified by means of a certificate issued by the responsible authority in the Member State in accordance with Regulation (EU) 2016/1191. In the case of prospective foreign employees, the above checks may be carried out on the basis of equivalent certificates issued by the country of origin, such as a ‘certificate of good conduct’. (b) Furthermore, the process and criteria to establish personnel’s trustworthiness may have to consider whether: (1) the information systems and data to be accessed have been associated with a high severity of the safety consequences with the risk assessment process under [IS.I.OR.205](#_DxCrossRefBm1749084227); (2) controls or mitigating measures for risk treatment identified during the risk analysis rely on organisational/operational procedures — for instance, correct configuration and administration of information technologies, database operations, information security monitoring, etc. In such cases, the personnel who have administrator rights or unsupervised and unlimited access to the systems and data mentioned in (a)(1), or the personnel who applies the measures under above point (b)(2), may be subject to more stringent criteria. (c) Intelligence and any other relevant information may be gathered by screening and analysing public sources such as social media and websites, within the limits set by relevant national laws and regulations. (d) Some organisations subject to Part-IS may also be subject to Regulation (EU) 2015/1998 that requires successful completion of background checks for personnel in certain roles, as well as a mechanism for the ongoing review of these checks. In such cases the organisation may consider suitable for the establishment of the personnel’s identity and trustworthiness required under Part-IS, in relation to their role, the process and the relevant criteria defined in Regulation (EU) 2015/1998 for standard and enhanced background checks. However, it should be noted that compliance with the provisions for the establishment of identity and trustworthiness under Part-IS does not constitute compliance with the provisions on background checks as defined in Regulation (EU) 2015/1998.