ICAO Annex 17

EASA Part 145 and Cyber Security Auditing Requirements

read more
A digital fingerprint surrounded by cybersecurity icons, such as padlocks and data protection symbols, representing information security auditing. The Sofema Aviation Services logo is in the top-left corner, with a text overlay focusing on EASA Part 145 auditing of information and cybersecurity requirements.

February 18, 2025

Steven Bentley

Sofema Aviation Services (SAS) Considers the Elements to be considered related to Information & Cyber Security Auditing within an EASA Part 145 Organisation As cybersecurity becomes a regulatory focus, EASA Part 145 audits will incorporate cyber resilience checks within maintenance organizations. National Aviation Authorities (NAAs) and internal compliance managers will be responsible for assessing the security of maintenance data, IT systems,…

EASA Reference Listing for Aviation Cyber Security Initiatives – R1

read more
A professional pointing at a digital interface displaying documents and a security lock icon, representing the EASA Reference Listing for Aviation Cyber Security Initiatives – R1.

February 14, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers a number of core documents used in support of EASA compliant cyber security initiatives. AMC 20-42 Airworthiness Information Security Risk Assessment Date: June 2023Description: Guidance for assessing airworthiness information security risks, including threats and mitigations. COMMISSION DELEGATED REGULATION (EU) 2022/1645 Date: July 2022Description: Rules for managing aviation information security risks impacting safety. COMMISSION IMPLEMENTING REGULATION (EU) 2023/203 Date: October 2022Description:…

EASA Cyber Security – Addressing Stakeholder Needs

read more
Business professional holding a holographic airplane, symbolizing EASA cyber security addressing aviation stakeholder needs

January 29, 2025

Steven Bentley

Sofema Aviation Services (SAS) takes a view on the role of the EASA Cyber Security Framework to address Stakeholder Needs, Legal Basis, and Policies for Collaboration and Information Sharing. Introduction – Stakeholder Needs Stakeholders in the aviation ecosystem include airlines, airports, air navigation service providers (ANSPs), manufacturers, maintenance organizations, and authorities. Their needs within the EASA Cyber Security focus on: Risk Management Identifying Threats: Stakeholders…

Cyber Security – EASA’s STORM initiative —Shared Trans-Organisational Risk Management

read more
Digital shield symbolizing cyber security, surrounded by data elements and network icons, representing EASA’s STORM initiative for shared trans-organizational risk management in aviation.

January 27, 2025

Steven Bentley

Sofema Aviation Services (SAS)  tackles the challenge of addressing cyber security threats within EASA-regulated organizations, focusing on EASA’s STORM (Shared Trans-Organisational Risk Management) Introduction EASA’s STORM initiative—Shared Trans-Organisational Risk Management addresses the interconnected risks within the aviation ecosystem, recognizing that risks cannot be managed in isolation due to the increasing digitization and interdependencies across stakeholders….