Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
ATM/ANS.OR.D.010 Security management
Available versions for ERULES-1963177438-3012
Regulation (EU) 2017/373
found in: ATM/ANS Provision of Services (2017/373) (Feb 2023)
Regulation (EU) 2023/203
found in: ATM/ANS Provision of Services (2017/373) (Mar 2025)
From
ATM/ANS Provision ... (Mar 2025)
ATM/ANS Provision ... (Feb 2023)
From section
To
ATM/ANS Provision ... (Mar 2025)
ATM/ANS Provision ... (Feb 2023)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
ATM/ANS.OR.D.010 Security management Regulation (EU) 2017/373 (a) Air navigation services and air traffic flow management providers and the Network Manager shall, as an integral part of their management system as required in point [ATM/ANS.OR.B.005](#_DxCrossRefBm1726554962), establish a security management system to ensure: (1) the security of their facilities and personnel so as to prevent unlawful interference with the provision of services; (2) the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised. (b) The security management system shall define: (1) the procedures relating to security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination; (2) the means designed to detect security breaches and to alert personnel with appropriate security warnings; (3) the means of controlling the effects of security breaches and to identify recovery action and mitigation procedures to prevent re-occurrence. (c) Air navigation services and air traffic flow management providers and the Network Manager shall ensure the security clearance of their personnel, if appropriate, and coordinate with the relevant civil and military authorities to ensure the security of their facilities, personnel and data. (d) Air navigation services and air traffic flow management providers and the Network Manager shall take the necessary measures to protect their systems, constituents in use and data and prevent compromising the network against information and cyber security threats which may have an unlawful interference with the provision of their service.
ATM/ANS.OR.D.010 Security management Regulation (EU) 2023/203 (a) Air navigation services and air traffic flow management providers and the Network Manager shall, as an integral part of their management system as required in point [ATM/ANS.OR.B.005](#_DxCrossRefBm647742120), establish a security management system to ensure: (1) the security of their facilities and personnel so as to prevent unlawful interference with the provision of services; (2) the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised. (b) The security management system shall define: (1) the procedures relating to security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination; (2) the means designed to detect security breaches and to alert personnel with appropriate security warnings; (3) the means of controlling the effects of security breaches and to identify recovery action and mitigation procedures to prevent re-occurrence. (c) Air navigation services and air traffic flow management providers and the Network Manager shall ensure the security clearance of their personnel, if appropriate, and coordinate with the relevant civil and military authorities to ensure the security of their facilities, personnel and data. (d) Air navigation services and air traffic flow management providers and the Network Manager shall take the necessary measures to protect their systems, constituents in use and data and prevent compromising the network against information and cyber security threats which may have an unlawful interference with the provision of their service. [applicable until 21 February 2026 - Regulation (EU) 2017/373] (a) Air navigation services and air traffic flow management providers and the Network Manager shall, as an integral part of their management system as required in point [ATM/ANS.OR.B.005](#_DxCrossRefBm647742120), establish a security management system to ensure: (1) the security of their facilities and personnel so as to prevent unlawful interference with the provision of services; (2) the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised. (b) The security management system shall define: (1) the process and procedures relating to security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination; (2) the means designed to identify, monitor and detect security breaches and to alert personnel with appropriate security warnings; (3) the means to control the effects of security breaches and to identify recovery action and mitigation procedures to prevent re-occurrence. (c) Air navigation services and air traffic flow management providers and the Network Manager shall ensure the security clearance of their personnel, if appropriate, and coordinate with the relevant civil and military authorities to ensure the security of their facilities, personnel and data. (d) The aspects related to information security shall be managed in accordance with point [ATM/ANS.OR.B.005A](#_DxCrossRefBm647742050). *[applicable from 22 February 2026 - Regulation (EU) 2023/203]*