Commission Delegated Regulation (EU) 2022/1645, Information Security Management System for Design, Production and Aerodrome Organizations (Part-IS.D.OR)
Commission Delegated Regulation (EU) 2022/1645, Art. 2 and Annex
In force since .
A sector security regimes rule binding public and private bodies.
- Obligation class
- Security, Governance
As of .
What it requires
- This duty binds the organizations named in Article 2(1) of Commission Delegated Regulation (EU) 2022/1645: a production organization or design organization under Part 21, or an aerodrome operator or apron management service provider under Part-ADR.OR, subject to the exception Article 2(1) lists for organizations solely involved in ELA 2 aircraft. It reaches you if you declare that you are an essential or important entity under Directive (EU) 2022/2555 and you are one of them. The Regulation applies from (Article 8).
- Set up, implement and maintain an information security management system that sets a policy on information security, identifies and reviews information security risks, defines and implements risk treatment measures, implements internal and external reporting schemes, detects information security events, responds to and recovers from incidents, applies the measures the competent authority notifies, addresses its findings, and monitors your compliance (point IS.D.OR.200(a)).
- Run a continuous improvement process and document your key processes, procedures, roles and responsibilities (points IS.D.OR.200(b) and (c)).
- Identify the elements of your organization exposed to information security risks and your interfaces with other organizations, assign each information security risk with a potential impact on aviation safety a level under a predefined classification, and review and update the assessment when the elements, the interfaces, the information used or the lessons from incidents change (points IS.D.OR.205(a) to (d)).
- Develop measures to address unacceptable risks, implement them in a timely manner, check their continued effectiveness, inform the persons referred to in point IS.D.OR.240(a) and (b) and the other affected personnel of the outcome of the risk assessment, the corresponding threat scenarios and the measures to be implemented, and inform the organizations you share an interface with of any risk you share with them (points IS.D.OR.210(a) and (b)).
- Establish an internal reporting scheme to collect and evaluate information security events, implement measures to detect incidents and vulnerabilities and to respond to events that may develop into an information security incident, and implement measures to recover from incidents (points IS.D.OR.215 and IS.D.OR.220).
- After the competent authority notifies findings, identify the root cause or causes, define a corrective action plan and demonstrate the correction to the authority's satisfaction within the period agreed with it (point IS.D.OR.225).
- When you contract out any part of these activities, ensure that the contracted activities comply with the Regulation, that the contracted organization works under your oversight, and that the risks of the contracted activities are managed (point IS.D.OR.235(a)).
- Have the accountable manager or, for a design organization, the head of the design organization ensure that the resources needed to comply are available, establish and promote the information security policy, and appoint a person or group of persons to ensure compliance and to manage the compliance monitoring function (points IS.D.OR.240(a) to (c)).
- Keep archived and traceable records of approvals, contracts, key processes, risks and risk treatment measures, reported incidents and vulnerabilities, and events that may need reassessment, and keep the records of key processes, risks and risk treatment measures, and reported incidents and vulnerabilities for at least 5 years (point IS.D.OR.245).
Who enforces it
Enforcement body
The authority responsible for certifying and overseeing compliance with the Regulation, which is the competent authority designated under the regulation that governs each class of organization it covers (the competent authority designated under Part 21 for design and production organizations and under Part-ADR.OR for aerodrome operators and apron management service providers).
What this law does
Article 1 of Regulation (EU) 2022/1645 sets out the requirements to be met by the organizations referred to in Article 2 in order to identify and manage information security risks with potential impact on aviation safety.
Article 2(1) applies the Regulation to production organizations and design organizations subject to Subparts G and J of Section A of Annex I (Part 21) to Regulation (EU) No 748/2012, and to aerodrome operators and apron management service providers subject to Annex III (Part-ADR.OR) to Regulation (EU) No 139/2014.
Point IS.D.OR.200(a) requires the organization to set up, implement and maintain an information security management system with a policy on information security, risk identification and treatment, internal and external reporting schemes, detection of information security events, response to and recovery from incidents, and compliance monitoring. Point IS.D.OR.200(b) requires a continuous improvement process.
Point IS.D.OR.200(e) lets the competent authority approve an organization not to implement these requirements if it demonstrates that its activities, facilities, resources and services pose no information security risks with a potential impact on aviation safety to itself or to other organizations. Point IS.D.OR.205(a) requires the organization to identify all its elements that could be exposed to information security risks.
Point IS.D.OR.205(c) requires the organization to identify the information security risks that may have a potential impact on aviation safety and to assign each risk a level according to a predefined classification. Point IS.D.OR.205(d) requires the organization to review and update the risk assessment when the elements, the interfaces, the information used to classify risks or the lessons learnt from incidents change.
Point IS.D.OR.210(a) requires the organization to develop measures to address unacceptable risks, implement them in a timely manner and check their continued effectiveness. Point IS.D.OR.215(a) requires an internal reporting scheme to collect and evaluate information security events, including those to be reported externally.
Point IS.D.OR.220 requires measures to detect incidents and vulnerabilities, measures to respond to events that may develop into an information security incident, and measures to recover from incidents. Point IS.D.OR.225(a) requires the organization, after the competent authority notifies findings, to identify the root causes, define a corrective action plan and demonstrate the correction to the authority's satisfaction.
Point IS.D.OR.235(a) requires the organization to ensure that the activities it contracts out comply with the Regulation and that the contracted organization works under its oversight. Point IS.D.OR.240(a) requires the accountable manager to ensure that the resources needed to comply are available, to establish and promote the information security policy and to demonstrate a basic understanding of the Regulation.
Point IS.D.OR.245 requires the organization to keep archived and traceable records of approvals, contracts, key processes, risks and risk treatment measures, reported incidents and vulnerabilities, and events that may need reassessment. The records of key processes, of risks and risk treatment measures, and of reported incidents and vulnerabilities are kept for at least 5 years. The Regulation applies from .
Article 4(1) treats compliance with equivalent security requirements laid down in accordance with Article 14 of Directive (EU) 2016/1148 as compliance with this Regulation. Directive (EU) 2022/2555 repealed Directive (EU) 2016/1148 with effect from , and references to the repealed Directive are construed as references to Directive (EU) 2022/2555.
The authority responsible for certifying and overseeing compliance is, for each class of organization, the competent authority designated under the regulation that governs that class (Article 5(1)). Article 131 of Regulation (EU) 2018/1139 requires Member States to lay down the rules on penalties applicable to infringement of that Regulation and of the delegated and implementing acts adopted on the basis of it.
The Regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.
When LexLint raises it
When your app profile says your app runs an essential service.