Blog

EASA Part 145 Cyber Security Compliance: Duties and Responsibilities Under IS.I.OR.240

read more
Business professional reviewing cybersecurity data on multiple screens, representing EASA Part 145 cyber security duties, accountabilities, and responsibilities compliant with IS.I.OR.240.

February 10, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers key elements related to Cyber Security Compliance within an EASA Part 145 Organisation. Regulation (EU) 2023/203, specifically IS.I.OR.240, mandates a structured and accountable approach to cybersecurity. Recognizing the critical role of robust cybersecurity practices requires EASA Part 145 organizations to understand duties, accountabilities, and responsibilities to maintain compliance and safeguard sensitive information. This document provides a breakdown of key roles—Accountable Manager, Nominated Post Holder, Business Area Manager,…

Foundations of Aviation Security Threat and Risk Assessment

read more
A security professional holding a laptop, symbolizing the critical role of aviation security threat assessment and risk management. The background features a digital security interface, highlighting the importance of safeguarding aviation operations, passengers, and assets. The Sofema Aviation Services (SAS) logo is displayed, along with the text: "Foundations of Aviation Security Threat and Risk Assessment.

February 10, 2025

Steven Bentley

Sofema Aviation Services (SAS) www.sassofia.com considers the role of Aviation Security as a pillar of the global aviation industry, ensuring the safety of passengers, crew, and assets. The foundations of aviation security threat and risk assessment are rooted in structured methodologies that identify vulnerabilities, evaluate threats, and implement mitigating actions. For entities operating within EASA…

Cyber Integration into an EASA Part 145 Organization – Risk Management Framework

read more
A digital image featuring a business professional interacting with a risk management dashboard, highlighting key cybersecurity elements such as data protection, analytics, and compliance. The Sofema Aviation Services (SAS) logo appears in the top left corner, with the text: "Cyber Integration into an EASA Part 145 Organization Risk Management Framework." The image represents the importance of cyber risk management in aviation maintenance organizations under EASA regulations.

February 07, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the challenges related to phishing, ransomware, data breaches, and insider threat exposures (both intentional and accidental) within the framework of an EASA Part 145 organization. Challenges in Cybersecurity for Part 145 Organizations EASA Part 145 organizations, as integral components of the aviation safety chain, face distinct challenges in managing information…

Cyber Security & Information Security Training for EASA Part 145 Organizations

read more
A digital image featuring a commercial aircraft with a futuristic cybersecurity network overlay, symbolizing the increasing role of cybersecurity and information security in EASA Part 145 organizations. The text highlights "Cyber Security & Information Security Training for EASA Part 145 Organizations" as part of a Sofema Aviation Services (SAS) blog series on cybersecurity.

February 07, 2025

Steven Bentley

Sofema Online (SOL) considers the training requirements to support EASA Part 145 Organizations in respect of Information and Cyber Security Introduction to the Primary Objective – Ensure all levels of staff understand their roles and responsibilities in managing cyber security risks in compliance with Regulation (EU) 2023/203. Accountable Executive & Leadership Team (C-Level) Duration: 1 Day (Executive Briefing) Target Audience: Accountable…