Navigate / EASA
AMC1 IS.D.OR.220(b) Information security incidents — detection, response and recovery

ED Decision 2023/009/R

(a) INCIDENTS

The organisation should take into account the following aspects when establishing compliance with the objectives contained in point IS.D.OR.220(b) relative to incidents:

(1) Preparation of procedures and delineation of roles and responsibilities to respond in a timely, effective and orderly manner to any relevant information security incidents.

(2) The response procedure should:

(i) consider the warnings, unitary or combined, from IS.D.OR.220(a)

(ii) establish, in accordance with IS.D.OR.220(b)(2), a containment strategy for each asset category considering the potential worst-case effect and the mission constraints, and provide criteria indicating when the incident is contained;

(iii) define, in accordance with IS.D.OR.220(b)(3), the acceptable impact on safety and information security of each asset within the scope when they fail due to the materialisation of a threat scenario.

(3) The response time should be commensurate with the impact level assessed in (2)(iii).

(4) The response measures implemented under IS.D.OR.220(b) should be based on the response procedure referred to in the point (a)(2) and they should, in particular, consider the following:

(i) the maximum acceptable safety level degradation of the assets within the scope of incident;

(ii) the actions, such as resistance, containment, deception and control of the possible ways systems can fail, which will contribute to achieving the acceptable safety level degradation identified in point (i) while minimising the impact on operations;

(iii) the resources required to implement the actions specified in point (ii).

(5) The response time and the measures should take into account the potential immediate negative impact on safety if the measure is taken before it has been fully verified that it would not cause additional immediate safety impacts.

(b) VULNERABILITIES

The organisation should take into account the following aspects when establishing compliance with the objectives contained in point IS.D.OR.220(b) relative to vulnerabilities:

(1) Establishment of a vulnerability management strategy defining procedures, roles and responsibilities to respond in a timely, effective and orderly manner to any detected relevant vulnerabilities.

(2) The response measures implemented under point IS.D.OR.220(b) should be based on the maximum acceptable risk of the items within the scope of the vulnerability, considering the worst-case scenario of the vulnerability being exploited.

(3) The response time should be commensurate with the pre-triage done on the warnings and the assessment of the potential impact of the vulnerability, if it is exploited.