ED Decision 2023/010/R
The competent authority should define and document the scope of the ISMS, by determining activities, processes, supporting systems, and identifying those which may have an impact on aviation safety.
The information security policy should be endorsed by the person identified as per IS.AR.225(a) and reviewed at planned intervals or if significant changes occur. Moreover, the policy should cover at least the following aspects with a potential impact on aviation safety by:
(a) committing to comply with applicable legislation, consider relevant standards and best practices;
(b) setting objectives and performance measures for managing information security;
(c) defining general principles, activities, processes for the competent authority to appropriately secure information and communication technology systems and data;
(d) committing to apply ISMS requirements into the processes of the competent authority;
(e) committing to continually improve towards higher levels of information security process maturity as per IS.AR.235;
(f) committing to satisfy applicable requirements regarding information security and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation;
(g) assigning information security as one of the essential responsibilities for all managers;
(h) committing to promote the information security policy through training or awareness sessions within the competent authority to all personnel on a regular basis or upon modifications;
(i) encouraging the implementation of a ‘Just-Culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents;
(j) committing to communicate the information security policy to all relevant parties, as appropriate.
Note: A significant change is a notable alteration or modification that has a meaningful impact on the competent authority operations, such as a structural change within the authority due to reorganisations, a change in the business processes (e.g. working from home, use of personal devices), a technological evolution (e.g. distributed computing resources, artificial intelligence/machine learning) or an evolution in the threat landscape.
Loading collections...