Incident Management

Contracting Considerations for Cyber Risk Management (IS.I.OR.235)

read more
Cyber Risk blog image.

April 08, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers key aspects related to the Information and Cyber Risk organisational exposure resulting from contracting activities To proactively manage cybersecurity risks through clear contractual arrangements, aviation organizations ensure they meet EASA requirements, mitigate risks, and contribute to overall aviation system security and safety. Organizations should: Review existing contracts for compliance gaps…

Cybersecurity Compliance in an EASA Part 145 Organization: Definitions and Scope

read more
Cybersecurity Compliance in an EASA Part 145

March 05, 2025

Steven Bentley

Sofema Aviation Services (SAS) www.sassofia.com considers key elements related to Cybersecurity Compliance within an EASA Part 145 Organisation. Introduction – Cybersecurity in Aviation Cybersecurity within EASA Part 145 Organisations involves protecting systems, networks, and data from unauthorized access, attacks, or disruptions. The focus is on safeguarding maintenance operations, ensuring safety, and securing data and systems. Compliance…

EASA Part 145 Information Security Management System (ISMS) Considerations

read more
Information Security Management System blog image

January 20, 2025

Steven Bentley

Sofema Aviation Services (SAS) www.sassofia.com reviews requirements & best practices related to the implementation of an effective Information Security Management System (ISMS) (Applicable from 22 February 2026 – Regulation (EU) 2023/203) Introduction To implement effective systems for 145.A.200A ISMS and 145.A.202 Internal Safety Reporting Scheme, an organization must establish a robust framework that integrates these systems…

A new training dedicated to Implementing an Information Cyber Security Program in an EASA Part 145 Organization is now available – Book your place

read more
Cyber Security Program image.

December 04, 2024

Steven Bentley

Sofema Aviation Services (SAS) www.sassofia.com is pleased to share that a new course has been added to our training portfolio: Implementing an Information Cyber Security Program in an EASA Part 145 Organization – 2 Days Available as a Classroom or Webinar training – Register at [email protected] What is the training about? This 2-day course provides aviation professionals within…