IRImplementing rule
ATM/ANS.OR.D.010Security management
(a)Air navigation services and air traffic flow management providers and the Network Manager shall, as an integral part of their management system as required in point ATM/ANS.OR.B.005, establish a security management system to ensure:
(1)the security of their facilities and personnel so as to prevent unlawful interference with the provision of services;
(2)the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised.
(b)The security management system shall define:
(1)the procedures relating to security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination;
(2)the means designed to detect security breaches and to alert personnel with appropriate security warnings;
(3)the means of controlling the effects of security breaches and to identify recovery action and mitigation procedures to prevent re-occurrence.
(c)Air navigation services and air traffic flow management providers and the Network Manager shall ensure the security clearance of their personnel, if appropriate, and coordinate with the relevant civil and military authorities to ensure the security of their facilities, personnel and data.
(d)Air navigation services and air traffic flow management providers and the Network Manager shall take the necessary measures to protect their systems, constituents in use and data and prevent compromising the network against information and cyber security threats which may have an unlawful interference with the provision of their service. [applicable until 21 February 2026 - Regulation (EU) 2017/373]
(a)Air navigation services and air traffic flow management providers and the Network Manager shall, as an integral part of their management system as required in point ATM/ANS.OR.B.005, establish a security management system to ensure:
(1)the security of their facilities and personnel so as to prevent unlawful interference with the provision of services;
(2)the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised.
(b)The security management system shall define:
(1)the process and procedures relating to security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination;
(2)the means designed to identify, monitor and detect security breaches and to alert personnel with appropriate security warnings;
(3)the means to control the effects of security breaches and to identify recovery action and mitigation procedures to prevent re-occurrence.
(c)Air navigation services and air traffic flow management providers and the Network Manager shall ensure the security clearance of their personnel, if appropriate, and coordinate with the relevant civil and military authorities to ensure the security of their facilities, personnel and data.
(d)The aspects related to information security shall be managed in accordance with point ATM/ANS.OR.B.005A. [applicable from 22 February 2026 - Regulation (EU) 2023/203]
IR · ATM/ANS.OR.D.010 — Regulation (EU) 2017/373 · Regulation (EU) 2023/203 · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025