Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.I.OR.210 Information security risk treatment

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.I.OR.210Information security risk treatment

(a)The organisation shall develop measures to address unacceptable risks identified in accordance with point IS.I.OR.205, implement them in a timely manner and check their continued effectiveness. Those measures shall enable the organisation to:

(1)control the circumstances that contribute to the effective occurrence of the threat scenario;

(2)reduce the consequences on aviation safety associated with the materialisation of the threat scenario;

(3)avoid the risks. Those measures shall not introduce any new potential unacceptable risks to aviation safety.

(b)The person referred to in point IS.I.OR.240(a) and (b) and other affected personnel of the organisation shall be informed of the outcome of the risk assessment carried out in accordance with point IS.I.OR.205, the corresponding threat scenarios and the measures to be implemented. The organisation shall also inform organisations with which it has an interface in accordance with point IS.I.OR.205(b) of any risk shared between both organisations.

IR · IS.I.OR.210 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.I.OR.210Information security risk treatment

Show the text

Unacceptable risks identified in accordance with point IS.I.OR.205 require a risk treatment process that may lead to the introduction of information security measures, often referred to as information security controls. For each identified risk, the organisation defines the specific risk treatment measures, methods or resources that will be used over the life cycle of each asset to: manage risk reduction; monitor and maintain each asset; update and fulfil activities for configuration management; manage supply chain; manage contracted services or service provider. The review of risk treatment measures includes life cycle considerations which are introduced by equipment, procedures and personnel. A risk treatment plan as an outcome of the risk management process includes a prioritisation of risks, the corresponding information on the objectives and means for risk treatment to reach an acceptable level of risk, as well as agreed timelines specifying when responsible personnel should have implemented the risk treatment measures. The timelines for the implementation of a risk treatment measure are subject to agreement by the personnel responsible for the implementation and are communicated to and accepted by the accountable manager of the organisation or delegated person(s). Any subsequent implementation delay, together with its cause, reason, rationale or necessity, is documented in the risk treatment plan, for risks that may lead to an unsafe condition. The delay is also subject to the acceptance by the accountable manager of the organisation or delegated person(s). This person may condition such acceptance on the implementation or availability of compensating controls or reactive measures to monitor, early detect and timely respond to the materialisation of the risk in treatment. In order to timely respond, the incident response team may be informed to trigger their preparedness. The risk treatment plan can act as a means of communication with the competent authority to demonstrate effective treatment of unacceptable risks. Similarly, this plan can be utilised to communicate to interfacing organisations how shared risks are controlled. In accordance with IS.I.OR.205(d), a regular or conditional review of the risk assessment is necessary, and this includes the review of the risk treatment measures developed under IS.I.OR.210(a) to identify whether they are still effective or they require adaptations. In addition, the organisation should also consider the potential impact on the effectiveness of risk treatment measures where a shared information security risk may arise as a result of the interaction between interfacing entities (see IS.I.OR.235 and related AMC).

GM · GM1 IS.I.OR.210 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.I.OR.210(a)Information security risk treatment

Show the text

(a)The risk treatment process should reach at least one of the objectives listed under IS.I.OR.210(a).

(b)When establishing compliance with the objectives under points IS.I.OR.210(a)(1) and IS.I.OR.210(a)(2), the organisation should take into account that:

(1)the measures developed under these points should be implemented according to a risk treatment plan with defined, risk-based priorities, objectives and agreed timelines and owners;

(2)life cycle considerations should be identified and associated to ensure continuous effectiveness of the information security measures including exchange of data with other entities;

(3)it should review and update the risk assessment, according to IS.I.OR.205(d), to evaluate whether the measures developed under these points introduce new unacceptable risks or modify existing risks in a way that they become unacceptable.

(c)Risk treatment should be documented and recorded, for example, in a risk registry, even if the risk has been avoided.

AMC · AMC1 IS.I.OR.210(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX II — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.I.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.I.OR.210 →

Metis opens with Avioverse in October 2026 · request early access.