Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
AMC1 IS.I.OR.205(e) Information security risk assessment
Available versions for ERULES-1963177438-21822
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
AMC1 IS.I.OR.205(e) Information security risk assessment ED Decision 2023/009/R SAFETY SUPPORT ASSESSMENT Non-ATS providers should conduct a safety support assessment as it is described in Regulation (EU) 2017/373 to assess the information security risk on their assets in regard to the service specification, e.g. integrity and availability, and to identify the residual risk. The non-ATS provider should share with the ATS provider, in an appropriate form, information on the residual risk and the impact on the services it provides to that ATS provider . The residual risk should be used to assess the potential impact on services and products that a non-ATS provider offers to an ATS provider. The ATS provider can use this as an input for its security risk assessment and, more importantly, to evaluate the potential impacts of these residual risks on safety.
##### AMC1 IS.I.OR.205(e) Information security risk assessment *ED Decision 2023/009/R* **SAFETY SUPPORT ASSESSMENT** Non-ATS providers should conduct a safety support assessment as it is described in [Regulation (EU) 2017/373](http://data.europa.eu/eli/reg_impl/2017/373/oj) to assess the information security risk on their assets in regard to the service specification, e.g. integrity and availability, and to identify the residual risk. The non-ATS provider should share with the ATS provider, in an appropriate form, information on the residual risk and the impact on the services it provides to that ATS provider. The residual risk should be used to assess the potential impact on services and products that a non-ATS provider offers to an ATS provider. The ATS provider can use this as an input for its security risk assessment and, more importantly, to evaluate the potential impacts of these residual risks on safety.