Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.AR.210 Information security risk treatment

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.AR.210Information security risk treatment

(a)The competent authority shall develop measures to address unacceptable risks identified in accordance with point IS.AR.205, shall implement them in a timely manner and shall check their continued effectiveness. Those measures shall enable the competent authority to:

(1)control the circumstances that contribute to the effective occurrence of the threat scenario;

(2)reduce the consequences to aviation safety associated with the materialisation of the threat scenario;

(3)avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety.

(b)The person referred to in point IS.AR.225(a) and other affected personnel of the competent authority shall be informed of the outcome of the risk assessment carried out in accordance with point IS.AR.205, the corresponding threat scenarios and the measures to be implemented. The competent authority shall also inform organisations with which it has an interface in accordance with point IS.AR.205(b) of any risk shared between competent authority and the organisation.

IR · IS.AR.210 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.210Information security risk treatment

Show the text

Unacceptable risks identified in accordance with point IS.I.OR.205 require a risk treatment process that may lead to the introduction of information security measures, often referred to as information security controls. For each identified risk, the competent authority should define the specific risk treatment measures, methods or resources that will be used over the life cycle of each asset to: — manage risk reduction; — monitor and maintain each asset; — update and fulfil activities for configuration management; — manage supply chain; — manage contracted services or service provider. The review of risk treatment measures should include life cycle considerations which are introduced by equipment, procedures and personnel. A risk treatment plan as an outcome of the risk management process should include a prioritisation of risks, the corresponding information on the objectives and means for risk treatment to reach an acceptable level of risk, as well as agreed timelines specifying by when responsible personnel should have implemented the risk treatment measures. The timelines for the implementation of a risk treatment measure should be agreed by the personnel responsible for the implementation and should be communicated to and accepted by the person identified in IS.AR.225(a). Any subsequent implementation delay, together with its cause, reason, rationale or necessity, should be documented in the risk treatment plan, for risks that may lead to an unsafe condition. The delay is also subject to the acceptance by the person identified in IS.AR.225(a). The identified person may condition such acceptance on the implementation or availability of compensating controls or reactive measures to monitor, early detect and timely respond to the materialisation of the risk in treatment. In order to timely respond, the incident response team may be informed to trigger their preparedness. The risk treatment plan can act as a means of communication with the Agency to demonstrate effective treatment of unacceptable risks. Similarly, this plan can be utilised to communicate to interfacing organisations how shared risks are controlled. In accordance with IS.AR.205(d), a regular or conditional review of the risk assessment is necessary, and this includes the review of the risk treatment measures developed under IS.AR.210(a) to identify whether they are still effective or they require adaptations. In addition, the competent authority should also consider the potential impact on the effectiveness of risk treatment measures where a shared information security risk may arise as a result of the interaction between interfacing entities (see IS.AR.220 and related AMC).

GM · GM1 IS.AR.210 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.210(a)Information security risk treatment

Show the text

(a)The risk treatment process should reach at least one of the objectives listed under IS.AR.210(a).

(b)When establishing compliance with the objectives under points IS.AR.210(a)(1) and IS.AR.210(a)(2), the competent authority should take into account that:

(1)the measures developed under these points should be implemented according to a risk treatment plan with defined, risk-based priorities, objectives and agreed timelines and owners;

(2)life cycle considerations should be identified and associated to ensure continuous effectiveness of the information security measures including exchange of data with other entities;

(3)it should review and update the risk assessment, according to IS.AR.205(d), to evaluate whether the measures developed under these points introduce new unacceptable risks or modify existing risks into a way that they become unacceptable.

(c)Risk treatment should be documented and recorded, for example, in a risk registry, even if the risk has been avoided.

AMC · AMC1 IS.AR.210(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.AR.210 →

Metis opens with Avioverse in October 2026 · request early access.