OTHER RISKS During the assessment phase, the following guidance regarding the associated security, privacy, and environmental risks may support the Member States. Security
(a)The implementation of the European regulatory framework for the protection of critical infrastructure as well as cybersecurity may lead to risk assessments that are relevant to the airspace considered. These risk assessments may be considered as components of the airspace risk assessment if they are reviewed to take into consideration the possible designation of a Uspace airspace.
(b)It is recommended that a security risk assessment be conducted to assess the security risks of an organisation which emerge from intentional, unauthorised electronic interaction. The necessary process steps and methodologies to conduct the security risk assessment will vary depending on the particular security risk assessment process that has been adopted.
(c)The methodology used to assess cybersecurity risks is very similar to the one used for physical security risks and, therefore, recommended to use it during the assessment phase. The process for the risk assessment and for the sharing of information security risks is illustrated in Figure 2 on the next page. This comprises several activities that need to be performed for each risk assessment.
(d)There are fixed inputs (marked with the letters A, B, C, D) that should be common to all risk assessments conducted by an organisation. These would be established as part of the overall corporate risk management process. The activities described may be conducted in a different order depending on the particular methodology used, and the activities and fixed inputs may have different names as well. Risk sharing can happen at any life cycle stage and should be dependent on agreed thresholds for reporting. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 2: Risk assessment and sharing of information according to EUROCAE ED-201A
(e)To ensure comparability and compatibility between the different security assessment methodologies and definitions of risk, it is recommended that the parties involved should have a common method for categorising risks and different classes of risks. The use of different methods may produce incomparable outputs that are unusable between the parties involved.
(f)The following principles may be used for risk sharing outputs where there is a safety impact identified between connected organisations and ecosystems using the same risk assessment method:
(1)Assurance that the outputs of the assessments produce results which are comparable internally and externally.
(2)Agreement upon common definitions for the connected interfaces (e.g. risk classes, vulnerabilities).
(3)Sharing information on assessed risks that have a potential safety impact on their partners, which relate to connecting networks, to sharing information, and to using thirdparty products.
(4)The use of different risk assessment matrices should be used according to the type of impact that is being assessed and shared (e.g. safety, capacity).
(5)An organisation may only compare and use the severity of same-type impacts, i.e. a safety impact with a safety impact; a safety impact cannot be compared with an organisational impact.
(6)Security protection
(i)The general type of protection (e.g. type of encryption standard).
(ii)The attribute being protected is important as it may be the case that one organisation protects availability, but the receiving organisation is concerned with protecting integrity.
(iii)The assurance of security protection which represents the quality it has been designed to operate. If the assurance level of the protection measures of the connected organisation is not broadly equivalent, then each connected system will either have to agree to share and manage the risk to an acceptable level for both organisations or individually manage the risk to an acceptable level. Privacy
(g)A risk assessment on privacy is aimed at assessing the privacy risks to third parties emerging from intentional or accidental visualisation, capture and/or retention of personal images or information through (close) overflight or hovering. The necessary process steps and methodologies to conduct the privacy risk assessment will vary depending on the particular privacy risk assessment process that has been adopted.
(h)The main legal reference regarding privacy risk assessment is Regulation (EU) 2016/679 (the General Data Protection Regulation (GDPR)). However, the GDPR only applies to ‘personal data’ as defined in its Article 4(1), not to commercial information, which will generally be covered by national laws. A privacy risk assessment is conducted to additionally ensure the security of thirdparty commercial data.
(i)Article 35 of the GDPR provides for the conduct of a data protection impact assessment (DPIA), where the processing of any personal data obtained is likely to result in a high risk to the rights and freedoms of the subjects of that data. This DPIA must describe the characteristics of the data treatment, the risks identified, and the mitigation measures adopted. A DPIA may be used to support the airspace risk assessment. Environmental
(j)An environmental risk assessment should assess the risks to people, wildlife and the natural environment which emerge from flights near built-up areas, especially schools and hospitals, protected landscape, natural reserves, along known wildlife migratory routes, or over lakes, rivers, and other bodies of water. The necessary process steps and methodologies to conduct an environmental risk assessment will vary depending on the particular environmental risk assessment process that has been adopted.
(k)Environmental risk assessments for UAS operations should ensure compliance with plans and programmes for which such environmental assessments have been carried out. Noise
(l)Regulations (EU) 2019/945 and 2019/947 lay down provisions as regards noise limitation of small UAS. They require manufacturers to minimise noise, and operators to follow the guidelines for reducing noise during operations. The assessment and management of environmental noise of small UAS should take these provisions into account. Directive 2002/49/EC relating to the assessment and management of environmental noise remains applicable, and the action plans required in paragraphs 5 to 7 of its Article 8 should be updated to include noise from UAS used in the ‘specific’ and ‘certified’ category. In effect, environmental airspace risk assessments ensure that UAS operations comply with these action plans regarding environmental noise.
(m)Many regulations on aircraft noise include airports, for example Regulation (EU) No 598/2014 on the establishment of rules and procedures with regard to the introduction of noise-related operating restrictions at Union airports within a Balanced Approach. Air quality
(n)Directive 2008/50/EC, implementing a common approach to ambient air quality and cleaner air for Europe, applies to the management of local air quality at and around airports. Assessments should determine whether drones whose lift and propulsion do not come solely from electric sources comply with this Directive. Protection of wildlife and the natural environment
(o)Concerns regarding aviation and wildlife generally focus on strikes against aircraft, mostly by birds. This is also a problem for unmanned aircraft. Such strikes could cause the unmanned aircraft to become uncontrollable, presenting a danger to people and property on the ground. Assessments should ensure that UAS operations avoid known wildlife migratory routes. Assessments should ensure that local laws on the protection of wild birds, notably through Directive 2009/147/EC on the conservation of wild birds, are respected. They should also ensure that Directive 92/43/EEC on the conservation of natural habitats and of wild fauna and flora, and in particular of Natura 2000 sites and other areas of special scientific interest and of outstanding natural beauty, is observed.