Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.I.OR.245 Record-keeping

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.I.OR.245Record-keeping

(a)The organisation shall keep records of its information security management activities

(1)The organisation shall ensure that the following records are archived and traceable:

(i)any approval received and any associated information security risk assessment in accordance with point IS.I.OR.200(e;)

(ii)contracts for activities referred to in point IS.I.OR.200(a)(9);

(iii)records of the key processes referred to in point IS.I.OR.200(d);

(iv)records of the risks identified in the risk assessment referred to in point IS.I.OR.205 along with the associated risk treatment measures referred to in point IS.I.OR.210;

(v)records of information security incidents and vulnerabilities reported in accordance with the reporting schemes referred to in points IS.I.OR.215 and IS.I.OR.230;

(vi)records of those information security events which may need to be reassessed to reveal undetected information security incidents or vulnerabilities.

(2)The records referred to in point (1)(i) shall be retained at least until 5 years after the approval has lost its validity.

(3)The records referred to in point (1)(ii) shall be retained at least until 5 years after the contract has been amended or terminated.

(4)The records referred to point (1)(iii), (iv) and (v) shall be retained at least for a period of 5 years.

(5)The records referred to in point (1)(vi) shall be retained until those information security events have been reassessed in accordance with a periodicity defined in a procedure established by the organisation.

(b)The organisation shall keep records of qualification and experience of its own staff involved in information security management activities

(1)The personnel’s qualification and experience records shall be retained for as long as the person works for the organisation, and for at least 3 years after the person has left the organisation.

(2)Members of the staff shall, upon their request, be given access to their individual records. In addition, upon their request, the organisation shall provide them with a copy of their individual records on leaving the organisation.

(c)The format of the records shall be specified in the organisation’s procedures.

(d)Records shall be stored in a manner that ensures protection from damage, alteration and theft, with information being identified, when required, according to its security classification level. The organisation shall ensure that the records are stored using means to ensure integrity, authenticity and authorised access.

IR · IS.I.OR.245 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.I.OR.245Record-keeping

Show the text

Records are required to document results achieved or to provide evidence of activities performed. Records become factual when recorded and cannot be modified. Therefore, they are not subject to version control. Even when a new record is produced covering the same issue, the previous record remains valid. The ‘approval received’ referred to in point (a)(1)(i) includes any ‘certificate’ received by the organisation when it is provided for by the implementing rule for its domain.

GM · GM1 IS.I.OR.245 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.I.OR.245(a)(1)(vi)&(a)(5) Record-keeping

Show the text

When complying with the requirements under points (a)(1)(vi) and (a)(5), the organisation should establish a data retention policy defining procedures to:

(a)manage relevant security data files;

(b)establish the periodical assessment of their content; and

(c)define the criteria to allow deletion of records of information security events when the objective of the requirement under (a)(5) has been met.

AMC · AMC1 IS.I.OR.245(a)(1)(vi) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.I.OR.245(a)(1)(vi)&(a)(5) Record-keeping

Show the text

The objective of the requirement under (a)(1)(vi) is to ensure detection of possible indication of information security incidents or vulnerabilities which are not obvious by normal operation (e.g. previously unknown situations), while the objective of the requirement under (a)(5) is to allow the necessary flexibility to control the volume of the stored information security events. Records of information security events include those events identified to be within the scope of the detection activities under IS.I.OR.220(a), as well as other information security data produced by assets that have been identified under IS.I.OR.205. A data retention policy clarifies what information should be stored or archived and for how long. Some guidance about data retention can be found in EUROCAE ED-206, Chapter 2.6. Once a data set completes its retention period, it can be deleted or moved as permanent historical data to a secondary or tertiary storage.

GM · GM1 IS.I.OR.245(a)(1)(vi) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.I.OR.245(c)&(d) Record-keeping

Show the text

When complying with the requirements under points (c) and (d) for all the records required by points IS.I.OR.245 (a) and (b), the organisation should consider the following:

(a)Records should be kept in paper form or in electronic format or a combination of both media. The records should remain accessible whenever needed within a reasonable time and usable throughout the required retention period. The retention period starts when the record has been created.

(b)Records data integrity, availability and authenticity should be protected in consistency with protection of corresponding operational data, and as such, should be within the scope of the ISMS.

(c)Storage systems should be protected against unauthorised access (i.e. data leakage attempts against personal data/modification of records) and thus should have information security measures implemented in consistency with the level of information security risk associated with them.

(d)Once records are not required to be retained anymore, the destruction of records and decommissioning of assets used for their storage should be implemented appropriately.

AMC · AMC1 IS.I.OR.245(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.I.OR.245(c)&(d) Record-keeping

Show the text

RECORDS ACCESSIBILITY THROUGHOUT THE RETENTION PERIOD It is recommended to follow best practices for data retention and, for data that may need to be restored, backup strategies, such as the use of automated backup tools, segregation or geographic separation of backup storage location(s), and to consider offline backups to prevent ransomware risks. These practices should be considered also when record-keeping is contracted to service providers with distributed resources. Special attention should be paid to significant hardware and software changes, ensuring that stored digital records remain accessible and readable (e.g. file system, application file format, forward compatible database versions, etc.). Paper-based information needs to be archived in an adequate environment, in which records are protected against degradation factors (e.g. excessive heat, light or humidity). RECORDS DATA INTEGRITY AND PROTECTION FROM UNAUTHORISED ACCESS A commonly used method to achieve authenticity and integrity protection is the use of digital signatures at document level. Digital signatures can be added to the document’s file (e.g. PDF) to ensure that a record has not been modified by someone other than its author (integrity) and that the author is who is expected to be (authenticity). Moreover, to prevent unauthorised access, records can be protected, for example, by implementing a role-based access control (RBAC) approach, or certain records can be password protected at the file level. Commercial applications feature built-in basic password protection functions for their file formats. Access protection can also be achieved by protecting the environment where the individual records are stored (e.g. access protection on databases, file shares, directories, etc.).

GM · GM1 IS.I.OR.245(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX II — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.I.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.I.OR.245 →

Metis opens with Avioverse in October 2026 · request early access.