BlogSeries

EASA Cyber Security – Guidance on Performing a Product and Part Security Risk Assessment (PISRA)

read more
A close-up of a hand interacting with a digital interface displaying "RISK MANAGEMENT" and various security-related icons. The image includes the Sofema Aviation Services (SAS) logo and a blog series banner on cyber security, with the title "EASA Cyber Security Guidance on Performing a Product and Part Security Risk Assessment (PISRA).

March 12, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers key aspects in relation to the process for the Security Risk Assessment identified in ED-202A Section 2.1.1 (PISRA). ED-202A Section 2.1.1 is an acceptable means of compliance for performing the PISRA for products and parts under Annex I (Part 21) to Regulation (EU) No 748/2012. Additional guidance material for the…

Overview of Regulation (EU) 2023/203 and Its Relevance to Part 145 Organizations

read more
A digital interface displaying cybersecurity-related graphics, including aircraft symbols and data analytics, with a Sofema Aviation Services logo in the top-left corner. The text overlay highlights a blog series on cybersecurity, focusing on Regulation (EU) 2023/203 and its impact on Part 145 organizations.

February 27, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers key elements related to Cyber Security Compliance within an EASA Part 145 Organizations Regulation (EU) 2023/203 was introduced to establish a framework for managing information security risks within the aviation sector, particularly focusing on their potential impact on aviation safety. Note – EASA Part 145 Organizations have until 22 February…

Meeting EASA Information & Cyber Security Compliance Without Adding Manpower

read more
A person typing on a laptop keyboard with cybersecurity-themed digital overlays, including code and security elements. The Sofema Aviation Services logo is in the top-left corner, with a text overlay discussing EASA information and cybersecurity compliance without increasing manpower.

February 19, 2025

Steven Bentley

Sofema Online (SOL) takes a deep dive into meeting EASA Information Security & implementation challenges without the need for additional manpower. Introduction IT and cybersecurity are so specific that companies often have to hire new people or even hire outside people to set up, manage and test/audit. Concerns regarding the reliance on external cybersecurity consultants…

EASA Part 145 Cyber Security Responsibilities – Maintaining Headcount

read more
A close-up of a person using a laptop, with digital security icons overlayed, representing cybersecurity responsibilities within an EASA Part 145 organization.

February 14, 2025

Steven Bentley

Sofema Aviation Services (SAS) is considering the development of an EASA Part 145 Information Security Management (Cyber) System to ensure compliance while maintaining the existing headcount. Introduction In an EASA Part 145 organization, where recruitment is constrained, cyber security responsibilities must be managed effectively by leveraging existing resources, optimizing processes, and implementing automation. A typical EASA Part 145 organization with 100 employees can meet cyber security responsibilities under IS.I.OR.240 without additional recruitment by…

logo-300x79
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.