IRImplementing rule
IS.AR.210Information security risk treatment
(a)The competent authority shall develop measures to address unacceptable risks identified in accordance with point IS.AR.205, shall implement them in a timely manner and shall check their continued effectiveness. Those measures shall enable the competent authority to:
(1)control the circumstances that contribute to the effective occurrence of the threat scenario;
(2)reduce the consequences to aviation safety associated with the materialisation of the threat scenario;
(3)avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety.
(b)The person referred to in point IS.AR.225(a) and other affected personnel of the competent authority shall be informed of the outcome of the risk assessment carried out in accordance with point IS.AR.205, the corresponding threat scenarios and the measures to be implemented. The competent authority shall also inform organisations with which it has an interface in accordance with point IS.AR.205(b) of any risk shared between competent authority and the organisation.
IR · IS.AR.210 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025