Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM1 Article 4(2) Requirements arising from other Union legislation
Available versions for ERULES-1963177438-24036
ED Decision 2025/013/R
found in: Information Security (2023/203 and 2022/1645) Part-IS (Dec 2025)
Version
Information Securi... (Dec 2025)
Section
Share
Version
Show details
Hide details
Version
##### GM1 Article 4(2) Requirements arising from other Union legislation *ED Decision 2025/013/R* Notwithstanding the equivalence between the requirements in [Regulation (EU) 2022/1645](http://data.europa.eu/eli/reg_del/2022/1645/oj) and the cybersecurity requirements contained in point 1.7 of the Annex to [Regulation (EU) 2015/1998](http://data.europa.eu/eli/reg_impl/2015/1998/oj), in order to ensure effective management of safety consequences by leveraging the requirements of Regulation (EU) 2015/1998, organisations need to consider the differences in the scope of the rules in terms of which elements are covered under the two different regulatory frameworks. Taking the example of an airport operator, elements such as body scanners, X-ray machines and anti-RPAS systems fall under the scope of the requirements of point 1.7 of the Annex to Regulation (EU) 2015/1998. Elements such as runway lighting control systems and safety training databases fall under the scope of aviation safety rules. On the other hand, the protection of information and the verification of trustworthiness and identity can be considered element that overlap between the two frameworks. Consequently, an organisation that has developed a system in accordance with point 1.7 of the Annex to Regulation (EU) 2015/1998 can use it to address safety issues by extending the scope of the system, where necessary, to ensure that all safety-related elements are included. Moreover, compliance with point [IS.D.OR.230](#_DxCrossRefBm1749084243) has to be ensured.