Navigate / EASA
AMC1 IS.AR.230(a)(1)(iv)&(a)(4) Record-keeping

ED Decision 2023/010/R

When complying with the requirements under points (a)(1)(iv) and (a)(4), the competent authority should establish a data retention policy defining procedures to:

(a) manage relevant information security data files;

(b) establish the periodical assessment of their content; and

(c) define the criteria to allow deletion of records of information security events when the objective of requirement (a)(4) has been met.