EASA Part 145

EASA Part 145 Cyber Security Responsibilities – Maintaining Headcount

read more
A close-up of a person using a laptop, with digital security icons overlayed, representing cybersecurity responsibilities within an EASA Part 145 organization.

February 14, 2025

Steven Bentley

Sofema Aviation Services (SAS) is considering the development of an EASA Part 145 Information Security Management (Cyber) System to ensure compliance while maintaining the existing headcount. Introduction In an EASA Part 145 organization, where recruitment is constrained, cyber security responsibilities must be managed effectively by leveraging existing resources, optimizing processes, and implementing automation. A typical EASA Part 145 organization with 100 employees can meet cyber security responsibilities under IS.I.OR.240 without additional recruitment by…

Cultural Resistance & Staff Awareness in EASA Part 145 Cybersecurity

read more
A close-up of hands typing on a keyboard, symbolizing cybersecurity awareness and cultural resistance within EASA Part 145 organizations.

February 14, 2025

Steven Bentley

Sofema Online (SOL) examines key aspects of Cultural Resistance in the implementation of cybersecurity within EASA Part 145 organizations. Introduction – Understanding Cultural Resistance in Cybersecurity One of the biggest challenges in implementing Information & Cyber Security within an EASA Part 145 organization is cultural resistance. Many aviation maintenance personnel, including engineers, technicians, and administrative…

Cybersecurity Reporting Procedure for EASA Part 145 Organizations Purpose

read more
A laptop displaying a digital cybersecurity framework, symbolizing the structured approach to cybersecurity reporting within EASA Part 145 organizations.

February 13, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers reporting methods and criteria within the EASA Part 145 Information Security Management (Cyber) System while maintaining the existing headcount. To establish a unified procedure for managing cybersecurity-related events, ensuring compliance with EU regulations, and safeguarding aviation safety in accordance with Commission Implementing Regulation (EU) 2023/203 and related EASA regulatory frameworks….

EASA Part 145 Cyber Security Compliance: Duties and Responsibilities Under IS.I.OR.240

read more
Business professional reviewing cybersecurity data on multiple screens, representing EASA Part 145 cyber security duties, accountabilities, and responsibilities compliant with IS.I.OR.240.

February 10, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers key elements related to Cyber Security Compliance within an EASA Part 145 Organisation. Regulation (EU) 2023/203, specifically IS.I.OR.240, mandates a structured and accountable approach to cybersecurity. Recognizing the critical role of robust cybersecurity practices requires EASA Part 145 organizations to understand duties, accountabilities, and responsibilities to maintain compliance and safeguard sensitive information. This document provides a breakdown of key roles—Accountable Manager, Nominated Post Holder, Business Area Manager,…

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.