Commission Implementing Regulation (EU) 2023/203, External Reporting of Information Security Incidents and Vulnerabilities in Aviation (IS.I.OR.230)
Commission Implementing Regulation (EU) 2023/203, IS.I.OR.230
In force since .
A vulnerability and incident reporting rule binding public and private bodies.
- Obligation class
- Reporting, Security
As of .
What it requires
- This duty binds the organizations named in Article 2(1) of Commission Implementing Regulation (EU) 2023/203: a Part-145 maintenance organization, a Part-CAMO continuing airworthiness management organization, a Part-ORO air operator, an approved training organization, an aircrew aero-medical center, a flight simulation training device operator, an air traffic controller training organization or aero-medical center, an organization subject to Part-ATM/ANS.OR, or a U-space service provider or single common information service provider, subject to the exceptions Article 2(1) lists. It reaches you if you declare that you are an essential or important entity under Directive (EU) 2022/2555 and you are one of them. The Regulation applies from , and from to the air navigation service provider of the European Geostationary Navigation Overlay Service (Article 16).
- Report to your competent authority any information security incident or vulnerability that may represent a significant risk to aviation safety; where it affects an aircraft or associated system or component, also report it to the design approval holder, and where it affects a system or constituent you use, to the organization responsible for its design (point IS.I.OR.230(b)).
- Submit a notification as soon as you know of the condition, and a report as soon as possible and not exceeding 72 hours from the time you know of it unless exceptional circumstances prevent this, in the form your competent authority defines (point IS.I.OR.230(c), points (1) and (2)).
- Submit a follow-up report on the actions you have taken or intend to take to recover and to prevent similar incidents as soon as those actions are identified (point IS.I.OR.230(c), point (3)).
- Operate an information security reporting system that complies with Regulation (EU) No 376/2014 and its delegated and implementing acts where that Regulation is applicable to you (point IS.I.OR.230(a)).
Who enforces it
Enforcement body
The authority responsible for certifying and overseeing compliance with the Regulation, which is the competent authority designated under the regulation that governs each class of organization it covers.
What this law does
Point IS.I.OR.230(b) requires the organization to ensure that any information security incident or vulnerability that may represent a significant risk to aviation safety is reported to its competent authority.
Where the incident or vulnerability affects an aircraft or associated system or component, the organization also reports it to the design approval holder, and where it affects a system or constituent the organization uses, to the organization responsible for the design of that system or constituent.
Point IS.I.OR.230(c) requires a notification as soon as the condition is known, a report as soon as possible and not exceeding 72 hours from the time the condition has been known to the organization, and a follow-up report on the recovery and prevention actions. The report is made in the form the competent authority defines and contains all relevant information about the condition known to the organization.
Point IS.I.OR.230(a) requires an information security reporting system that complies with Regulation (EU) No 376/2014 and its delegated and implementing acts where that Regulation is applicable to the organization.
Article 5(2) treats the cybersecurity requirements in point 1.7 of the Annex to Implementing Regulation (EU) 2015/1998 as equivalent to the requirements of this Regulation for an operator or entity in the national civil aviation security programs, except as regards point IS.I.OR.230, which must be complied with as such. The Regulation applies from , and from to the air navigation service provider of the European Geostationary Navigation Overlay Service.
The authority responsible for certifying and overseeing compliance is, for each class of organization, the competent authority designated under the regulation that governs that class (Article 6(1)). Article 131 of Regulation (EU) 2018/1139 requires Member States to lay down the rules on penalties applicable to infringement of that Regulation and of the delegated and implementing acts adopted on the basis of it.
When LexLint raises it
When your app profile says your app runs an essential service.