Navigate / EASA

IS.AR.205 Information security risk assessment

Regulation (EU) 2023/203

(a) The competent authority shall identify all the elements of its own organisation which could be exposed to information security risks. This shall include:

(1) the competent authority’s activities, facilities and resources, and the services the competent authority operates, provides, receives or maintains;

(2) the equipment, systems, data and information that contribute to the functioning of the elements referred to in point (1)

(b) The competent authority shall identify the interfaces that its own organisation has with other organisations, and which could result in the mutual exposure to information security risks.

(c) For the elements and interfaces referred to in points (a) and (b), the competent authority shall identify the information security risks which may have a potential impact on aviation safety.

For each identified risk, the competent authority shall:

(1) assign a risk level according to a predefined classification established by the competent authority;

(2) associate each risk and its level with the corresponding element or interface identified in accordance with points (a) and (b).

The predefined classification referred to in point (1) shall take into account the potential of occurrence of the threat scenario and the severity of its safety consequences. Through this classification, and taking into account whether the competent authority has a structured and repeatable risk management process for operations, the competent authority shall be able to establish whether the risk is acceptable or needs to be treated in accordance with point IS.AR.210.

In order to facilitate the mutual comparability of risks assessments, the assignment of the risk level per point (1) shall take into account relevant information acquired in coordination with the organisations referred to in point (b).

(d) The competent authority shall review and update the risk assessment carried out in accordance with points (a), (b) and (c) in any of the following cases:

(1) there is a change in the elements subject to information security risks;

(2) there is a change in the interfaces between the competent authority’s organisation and other organisations, or in the risks communicated by the other organisations;

(3) there is a change in the information or knowledge used for the identification, analysis and classification of risks;

(4) there are lessons learnt from the analysis of information security incidents.