Steven Bentley's posts

Should Maintenance Management Manuals be Home Grown or Outsourced?

read more
Maintenance Management Manuals blog image

April 23, 2025

Steven Bentley

Steve Bentley, FRAeS & CEO of Sofema, provides an honest answer – They Must Be Home Grown – however, they benefit from Strategic External Support Introduction In aviation maintenance, the question isn’t just who writes the manuals — it’s who lives and breathes them. Maintenance Management Manuals (MMMs) are not static documents; they are dynamic,…

EASA Information & Cyber Risk Assessment Methodology (Aligned with IS.I.OR.205)

read more

April 22, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the key features within the Information Security and Cyber Security Aviation Ecosystem Introduction to IS.I.OR.205 Key Components IS.I.OR.205 establishes a framework for identifying, evaluating, and managing information security risks within the aviation sector. The key components are: Identification of Elements at Risk (IS.I.OR.205(a)) Organizations must identify all components at risk,…

Achieve Cyber Resilience – Enrol in our Cybersecurity Part-IS Implementation for EASA Approved Organizations – 2 Days

read more
Cybersecurity Part-IS Implementation for EASA Approved Organizations SAS

April 22, 2025

Steven Bentley

Sofema Aviation Services (SAS) www.sassofia.com is pleased to share that a new course has been added to our training portfolio: Cybersecurity Part- IS Implementation for EASA Approved Organizations – 2 Days *New – Participants can now enrol Free of Charge (FOC) in a complementary 1-day Sofema Online (SOL) training to enhance their learning experience. What is the training about?…

Operational Stakeholder Responsibilities in ISMS Implementation and Aviation Safety (EASA)

read more
ISMS blog image

April 17, 2025

Steven Bentley

The successful implementation and management of an Information Security Management System (ISMS) in aviation safety under EASA regulations requires a coordinated effort from multiple stakeholders. Each stakeholder group—Management, Compliance, IT, and Operations—has distinct responsibilities, competence requirements, and training needs Under Regulations (EU) 2023/203 and 2022/1645, EASA outlines specific requirements for competence, training, and performance evaluation…