EASA Part 145

Cybersecurity Reporting Procedure for EASA Part 145 Organizations Purpose

read more
A laptop displaying a digital cybersecurity framework, symbolizing the structured approach to cybersecurity reporting within EASA Part 145 organizations.

February 13, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers reporting methods and criteria within the EASA Part 145 Information Security Management (Cyber) System while maintaining the existing headcount. To establish a unified procedure for managing cybersecurity-related events, ensuring compliance with EU regulations, and safeguarding aviation safety in accordance with Commission Implementing Regulation (EU) 2023/203 and related EASA regulatory frameworks….

EASA Part 145 Cyber Security Compliance: Duties and Responsibilities Under IS.I.OR.240

read more
Business professional reviewing cybersecurity data on multiple screens, representing EASA Part 145 cyber security duties, accountabilities, and responsibilities compliant with IS.I.OR.240.

February 10, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers key elements related to Cyber Security Compliance within an EASA Part 145 Organisation. Regulation (EU) 2023/203, specifically IS.I.OR.240, mandates a structured and accountable approach to cybersecurity. Recognizing the critical role of robust cybersecurity practices requires EASA Part 145 organizations to understand duties, accountabilities, and responsibilities to maintain compliance and safeguard sensitive information. This document provides a breakdown of key roles—Accountable Manager, Nominated Post Holder, Business Area Manager,…

Cyber Security & Information Security Training for EASA Part 145 Organizations

read more
A digital image featuring a commercial aircraft with a futuristic cybersecurity network overlay, symbolizing the increasing role of cybersecurity and information security in EASA Part 145 organizations. The text highlights "Cyber Security & Information Security Training for EASA Part 145 Organizations" as part of a Sofema Aviation Services (SAS) blog series on cybersecurity.

February 07, 2025

Steven Bentley

Sofema Online (SOL) considers the training requirements to support EASA Part 145 Organizations in respect of Information and Cyber Security Introduction to the Primary Objective – Ensure all levels of staff understand their roles and responsibilities in managing cyber security risks in compliance with Regulation (EU) 2023/203. Accountable Executive & Leadership Team (C-Level) Duration: 1 Day (Executive Briefing) Target Audience: Accountable…

Cybersecurity Responsibilities in EASA Part 145 Maintenance – Safety System Integration

read more
A digital illustration of an aircraft composed of glowing blue data points, symbolizing cybersecurity in aviation. A wireframe figure interacts with a tablet, emphasizing technology and cybersecurity integration. The Sofema Aviation Services logo is in the top left corner, with a blue banner stating "Blog Series: Cyber Security." The main text reads "Cybersecurity Responsibilities in EASA Part 145 Maintenance – Safety System Integration

February 05, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers a practical level of engagement for typical Small to Medium EASA Part 145 Maintenance Organisations. Introduction For an EASA Part 145 approved maintenance organization to achieve the integration of cybersecurity into the operational framework, including the Safety Management System (SMS), requires practical, resource-conscious strategies. Adapting a Risk Management Framework Train…