IRImplementing rule
IS.AR.215Information security incidents — detection, response and recovery
(a)Based on the outcome of the risk assessment carried out in accordance with point IS.AR.205 and the outcome of the risk treatment performed in accordance with point IS.AR.210, the competent authority shall implement measures to detect events that indicate the potential materialisation of unacceptable risks and which may have a potential impact on aviation safety. Those detection measures shall enable the competent authority to:
(1)identify deviations from predetermined functional performance baselines;
(2)trigger warnings to activate proper response measures, in case of any deviation.
(b)The competent authority shall implement measures to respond to any event conditions identified in accordance with point (a) that may develop or have developed into an information security incident. Those response measures shall enable the competent authority to:
(1)initiate the reaction of its own organisation to the warnings referred to in point (a)(2) by activating predefined resources and course of actions;
(2)contain the spread of an attack and avoid the full materialisation of a threat scenario;
(3)control the failure mode of the affected elements defined in point IS.AR.205(a).
(c)The competent authority shall implement measures aimed at recovering from information security incidents, including emergency measures, if needed. Those recovery measures shall enable the competent authority to:
(1)remove the condition that caused the incident, or constrain it to a tolerable level;
(2)restore a safe state of the affected elements defined in point IS.AR.205(a) within a recovery time previously defined by its own organisation.
IR · IS.AR.215 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025