Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 IS.I.OR.260(b) Continuous improvement
Available versions for ERULES-1963177438-21829
ED Decision 2023/009/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM1 IS.I.OR.260(b) Continuous improvement ED Decision 2023/009/R The ‘necessary improvement measures’ referred to in [IS.I.OR.260](#_DxCrossRefBm1193569542)(b)refer to correction or corrective actions to eliminate deficiencies or actions aimed at improving the effectiveness as well as the maturity of the ISMS. A process satisfying the criteria defined in [AMC1 IS.I.OR.260](#_DxCrossRefBm1193569654) should include the following aspects: (a) identifying the extent, impact, context and triggers of the deficiency, evaluating it according to some established criteria, analysing potential consequences for the ISMS including a potential existence in other areas; (b) deciding on corrections and their implementation to immediately limit the impact and manage the consequences of the deficiency as well as, as applicable, to control or eliminate it; (c) deciding on corrective actions required to eliminate the (root) cause(s) of the deficiency that are proportionate to the consequences; (d) reassessing the elements of the ISMS which may be affected by the implemented actions to ensure that no further risk is introduced; (e) verifying the implemented actions referred to in point (c) of [AMC1 IS.I.OR.260(b)](#_DxCrossRefBm1193569658); (f) reporting to and reviewing the outcomes of the process steps with the management (see point (d) of [AMC1 IS.I.OR.260(b)](#_DxCrossRefBm1193569658)); (g) documenting and evidencing the result of the process steps above (see point (e) of [AMC1 IS.I.OR.260(b)](#_DxCrossRefBm1193569658)).
##### GM1 IS.I.OR.260(b) Continuous improvement *ED Decision 2023/009/R* The ‘necessary improvement measures’ referred to in [IS.I.OR.260](#_DxCrossRefBm1749084280)(b)refer to correction or corrective actions to eliminate deficiencies or actions aimed at improving the effectiveness as well as the maturity of the ISMS. A process satisfying the criteria defined in [AMC1 IS.I.OR.260](#_DxCrossRefBm1749084392) should include the following aspects: (a) identifying the extent, impact, context and triggers of the deficiency, evaluating it according to some established criteria, analysing potential consequences for the ISMS including a potential existence in other areas; (b) deciding on corrections and their implementation to immediately limit the impact and manage the consequences of the deficiency as well as, as applicable, to control or eliminate it; (c) deciding on corrective actions required to eliminate the (root) cause(s) of the deficiency that are proportionate to the consequences; (d) reassessing the elements of the ISMS which may be affected by the implemented actions to ensure that no further risk is introduced; (e) verifying the implemented actions referred to in point (c) of [AMC1 IS.I.OR.260(b)](#_DxCrossRefBm1749084396); (f) reporting to and reviewing the outcomes of the process steps with the management (see point (d) of AMC1 IS.I.OR.260(b)); (g) documenting and evidencing the result of the process steps above (see point (e) of AMC1 IS.I.OR.260(b)).