Navigate / EASA

DPO.AR.A.015 Immediate reaction to an information security incident or vulnerability with an impact on aviation safety

Regulation (EU) 2023/1769

(a)       The Agency shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes.

(b)       Upon receiving the information referred to in point (a), the Agency shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability.

(c)       Measures taken in accordance with point (b) shall immediately be notified to all persons or organisations that shall comply with them under Regulation (EU) 2018/1139 and the delegated and implementing acts adopted on its basis. The Agency shall also notify those measures to the competent authorities of the Member States concerned.