RELATION BETWEEN CHANGES TO THE ISMS AND CONTINUOUS IMPROVEMENT Changes stemming from the continuous improvement process established by the organisation (see IS.I.OR.260) should be handled as any other change according to the guidelines in AMC1 IS.I.OR.255 and GM1 IS.I.OR.255.
EXAMPLE OF CHANGES THAT MAY HAVE AN IMPACT ON THE ISMS Below are some examples of changes that may have an impact on the ISMS, or which could lead to an unacceptable level of risk and therefore should be subject to scrutiny by the competent authority according to the provisions established under IS.I.OR.255:
(a)Changes to the scope of the ISMS, interfaces or related policies: The organisation expands its business functions, and integrates another company within its organisational structure. The organisation has identified non-conformities indicating an incorrect scope. The organisation amends its information security policy and/or information security objectives with a potential impact on aviation safety. Changes to the interfaces of the organisation resulting e.g. from modification in the insourced or outsourced activities.
(b)Changes in responsibilities and accountability as well as in the organisational structure involving the implementation and continuing monitoring of compliance with this Regulation: The accountable manager has delegated certain responsibilities under Part-IS to a person or a group of persons. The organisation contracts information security management activities as per IS.I.OR.235.
(c)Changes to the methodology used for risk management: The organisation changes the classification for likelihood or impact in their risk management methodology e.g. to obtain more granularity. The organisation implements changes to their risk treatment methodology. The organisation integrates its information security risk management into existing management systems.
(d)Changes to the security event management process: The organisation decides to contract security event management activities. The organisation changes the process to notify security events and the criteria to escalate to higher management for a quicker resolution. The organisation changes its policy for mitigating vulnerabilities. The organisation changes its incident recovery procedure.
EXAMPLE OF CHANGES THAT DO NOT HAVE AN IMPACT ON THE ISMS Not all operational changes related to information security have an impact on the ISMS, therefore not all changes are required to be reported to the competent authority, following the provisions established under IS.I.OR.255. The following scenarios may be representative of such changes: After a successfully detected security event which could have easily evolved to an incident, the organisation decides to roll out an extensive cyber security awareness campaign for all employees. Update in the staff training programme and/or training content as a result of the continuous improvement processes established within the organisation. The organisation replaces the software tool that it uses for encrypting sensitive files with another software solution. The organisation has decided to make an internal restructuring for business reasons, changing the names of departments or sections, without making any changes in the responsibilities and accountability (e.g. accountable manager) involving the ISMS of the organisation. The organisation decides to update an existing preventive control e.g. configuring a new firewall in its internal network.