Date: 2023-02-02Category: Not ApplicableState: Union GovernmentCountry: Europe
Commission Implementing Regulation (EU) 2023/203 of 27 October 2022 laying down rules for the application of Regulation (EU) 2018/1139 of the European Parliament and of the Council, as regards requirements for the management of information security risks with a potential impact on aviation safety for organisations covered by Commission Regulations (EU) No 1321/2014, (EU) No 965/2012, (EU) No 1178/2011, (EU) 2015/340, Commission Implementing Regulations (EU) 2017/373 and (EU) 2021/664, and for competent authorities covered by Commission Regulations (EU) No 748/2012, (EU) No 1321/2014, (EU) No 965/2012, (EU) No 1178/2011, (EU) 2015/340 and (EU) No 139/2014, Commission Implementing Regulations (EU) 2017/373 and (EU) 2021/664 and amending Commission Regulations (EU) No 1178/2011, (EU) No 748/2012, (EU) No 965/2012, (EU) No 139/2014, (EU) No 1321/2014, (EU) 2015/340, and Commission Implementing Regulations (EU) 2017/373 and (EU) 2021/664
Issued by European Commission
· Directorate-General for Mobility and Transport
This document, a non-legislative act published in the Official Journal of the European Union, outlines requirements for an organization's information security management. It includes multiple articles (Article 1 through Article 16) and annexes (Annex I through Annex IX). Specific requirements detailed in the annexes include the maintenance of records related to information security management activities (Annex I) and the qualifications and experience of staff involved in information security management (Annex II). The document is issued under the authority of the Commission, with the President listed as the signatory.
Key Entities Referenced
Article 4: A section within the document outlining specific provisions or regulations.
Commission: An unspecified commission, likely a part of the European Union structure, responsible for the actions described in the document.
Official Journal of the European Union: The official gazette of the European Union, where legal acts and other official documents are published.
ANNEX I: Appendix of the document specifying the organisation shall keep records of its information security management activities
ANNEX II: Appendix of the document specifying the organisation shall keep records of qualification and experience of its own staff involved in information security management activities
Article 1: A section within the document outlining specific provisions or regulations.
Article 2: A section within the document outlining specific provisions or regulations.
Article 3: A section within the document outlining specific provisions or regulations.
(Non-legislative acts)
Article 1
Article 2Article 3Article 4
Article 5
Article 6Article 7
Article 8
Article 9
Article 10
Article 11Article 12
Article 13
Article 14
Article 15
Article 16
Official Journal of the
European Union
For the Commission
The PresidentANNEX IANNEX II
The organisation shall keep records of its information security management activitiesThe organisation shall keep records of qualification and experience of its own staff involved in information security management
activitiesANNEX III
ANNEX IVANNEX V
ANNEX VIANNEX VIIANNEX VIIIANNEX IX