AMCAcceptable means of compliance
AMC to CS 25.1319 Equipment, systems and network information security protection
In showing compliance with CS 25.1319, the applicant may consider AMC 20-42, which provides acceptable means, guidance and methods to perform security risk assessments and mitigation for aircraft information systems. The term ‘adverse effects on the safety of the aeroplane’ limits the scope of this provision to security breaches that impact on the safety and airworthiness of the aeroplane and its operation, rather than security breaches that may impact on the systems that have no safety effect on the aeroplane. For example, while the manufacturer and the air operator may have real concerns about protecting a device that is used to process passenger credit cards and securing passenger information, EASA does not regard this as being subject to review and approval as part of the certification of the system, but instead as something that the air operator or manufacturer would address as part of their business practices and responsibilities to the customer. The term ‘mitigated as necessary’ clarifies that the applicant has the discretion to establish appropriate means of mitigation against security risks. The term ‘procedures and Instructions for Continued Airworthiness (ICA)’ clarifies that, while the ICA may be one mechanism for providing the necessary instructions to maintain airworthiness, the security protections may go beyond traditional ICA material, and also include other procedures provided to the air operator. This aligns with the existing practices among those applicants for which special conditions (SCs) have been issued to address the protection of the aircraft information systems’ security.
[Amdt 25/25]
AMC — CS-25 · ED Decision 2020/006/R · CS-25 Easy Access Rules · EAR revision 26 Jan 2023