ED Decision 2023/009/R
The organisation should define and document the scope of the ISMS, by determining activities, processes, supporting systems, and identifying those which may have an impact on aviation safety.
The information security policy should be endorsed by the accountable manager or, in the case of design organisations, by the head of the design organisation, and reviewed at planned intervals or if significant changes occur. Moreover, the policy should cover at least the following aspects with a potential impact on aviation safety by:
(a) committing to comply with applicable legislation, consider relevant standards and best practices;
(b) setting objectives and performance measures for managing information security;
(c) defining general principles, activities, processes for the organisation to appropriately secure information and communication technology systems and data;
(d) committing to apply ISMS requirements into the processes of the organisation;
(e) committing to continually improve towards higher levels of information security process maturity as per IS.D.OR.260;
(f) committing to satisfy applicable requirements regarding information security and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation;
(g) assigning information security as one of the essential responsibilities for all managers;
(h) committing to promote the information security policy through training or awareness sessions within the organisation to all personnel on a regular basis or upon modifications;
(i) encouraging the implementation of a ‘Just-(Culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents;
(j) committing to communicate the information security policy to all relevant parties, as appropriate.
Note: A significant change is a notable alteration or modification that has a meaningful impact on the organisation’s operations, such as a structural change within the organisation due to reorganisations, a change in the business processes (e.g. working from home, use of personal devices), a technological evolution (e.g. distributed computing resources, artificial intelligence/machine learning) or an evolution in the threat landscape.
Loading collections...