AviationBot
Navigate / EASA / INFORMATION SECURITY DEC 2025 / Implementing Regulation (EU) 2023/203 / ANNEX I -- INFORMATION SECURITY -- AUTHORITY REQUIREMENTS [PART-IS.AR] /

IS.AR.210 Information security risk treatment

EASA Logo

IS.AR.210 Information security risk treatment

Regulation (EU) 2023/203

(a) The competent authority shall develop measures to address unacceptable risks identified in accordance with point IS.AR.205, shall implement them in a timely manner and shall check their continued effectiveness. Those measures shall enable the competent authority to:

(1) control the circumstances that contribute to the effective occurrence of the threat scenario;

(2) reduce the consequences to aviation safety associated with the materialisation of the threat scenario;

(3) avoid the risks.

Those measures shall not introduce any new potential unacceptable risks to aviation safety.

(b) The person referred to in point IS.AR.225(a) and other affected personnel of the competent authority shall be informed of the outcome of the risk assessment carried out in accordance with point IS.AR.205, the corresponding threat scenarios and the measures to be implemented.

The competent authority shall also inform organisations with which it has an interface in accordance with point IS.AR.205(b) of any risk shared between competent authority and the organisation.

Frequently Asked Questions

The competent authority shall develop measures to address unacceptable risks identified in accordance with point IS.AR.205, implement them in a timely manner, and check their continued effectiveness. These measures must enable the authority to control circumstances contributing to the effective occurrence of the threat scenario, reduce consequences to aviation safety associated with materialisation of the threat scenario, and avoid the risks. The measures must not introduce any new potential unacceptable risks to aviation safety.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The measures must enable the competent authority to: (1) control the circumstances that contribute to the effective occurrence of the threat scenario; (2) reduce the consequences to aviation safety associated with the materialisation of the threat scenario; and (3) avoid the risks.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

Those measures shall not introduce any new potential unacceptable risks to aviation safety.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The person referred to in point IS.AR.225(a) and other affected personnel of the competent authority shall be informed of the outcome of the risk assessment carried out in accordance with point IS.AR.205, the corresponding threat scenarios, and the measures to be implemented.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The competent authority shall inform organisations with which it has an interface in accordance with point IS.AR.205(b) of any risk shared between the competent authority and the organisation.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The regulation is (EU) 2023/203.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The competent authority shall implement the measures in a timely manner and shall check their continued effectiveness.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The measures are intended to address unacceptable risks identified under IS.AR.205 by enabling the competent authority to control the circumstances that contribute to the effective occurrence of the threat scenario, reduce the consequences to aviation safety associated with the materialisation of the threat scenario, and avoid the risks.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

Related

AI for Aviation Professionals

Aviation.Bot is an AI tool that assists you with aviation compliance.