Navigate / EASA
GM1 IS.D.OR.200(a)(12) Information security management system (ISMS)

ED Decision 2023/009/R

COMPLIANCE MONITORING

For the purpose of compliance monitoring, internal audits should be conducted at planned intervals to provide assurance on the status of the ISMS to the management and to provide information on the following:

— conformity of the ISMS to the requirements of this Regulation and the organisation’s own requirements either stated in the information security policy, procedures and contracts or derived from information security objectives or outcomes of the risk treatment process;

— effective implementation and maintenance of the ISMS.

Internal audits should follow an independent approach and a decision-making process based on evidences. Moreover, when setting up an audit programme the importance of the processes concerned, and definitions of the audit criteria and scopes should be considered. Documented information should be retained evidencing the audit results, their reporting to the relevant management and the audit programme.