ISMS

Identifying ISMS Compliance Gaps within Organisational Business Areas

read more
ISMS Compliance blog image

April 28, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers areas of key exposure related to the implementation of ISMS As well as demonstrating compliance with Regulation (EU) 2023/203, Operators should focus on reducing exposure to cyber risks and operational disruptions, by improving business resilience and safety in line with EASA requirements. Finally, Operators should aim to strengthen stakeholder confidence…

Operational Stakeholder Responsibilities in ISMS Implementation and Aviation Safety (EASA)

read more
ISMS blog image

April 17, 2025

Steven Bentley

The successful implementation and management of an Information Security Management System (ISMS) in aviation safety under EASA regulations requires a coordinated effort from multiple stakeholders. Each stakeholder group—Management, Compliance, IT, and Operations—has distinct responsibilities, competence requirements, and training needs Under Regulations (EU) 2023/203 and 2022/1645, EASA outlines specific requirements for competence, training, and performance evaluation…

ISMS Requirements under IS.I.OR.200 (EU 2023/203)

read more
Digital padlock icon over source code representing cybersecurity, with text highlighting ISMS requirements under EU regulation, by Sofema Aviation Services.

April 07, 2025

Steven Bentley

Sofema Aviation Services (SAS) highlights ISMS in aviation safety, emphasizing EASA’s IS.I.OR.200 and its impact on European operations. An Information Security Management System (ISMS) under IS.I.OR.200 is a systematic framework for managing and securing information in aviation organisations. The ISMS aims to protect information assets, ensure operational and safety objectives are met, and manage risks…

Part 145 – Information Security Foundations – Cyber Threat Landscape

read more
A digital security interface featuring a glowing shield with a keyhole, symbolizing cybersecurity protection. A person’s hand is interacting with the interface, emphasizing digital security measures. The Sofema Aviation Services logo is in the top-left corner, with a text overlay discussing Part 145 information security foundations and the cyber threat landscape.

February 28, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the challenges related to phishing, ransomware, data breaches, and insider threat exposures (both intentional and accidental) within the context of EASA Part 145 organizations, together with a high-level mitigation review. Introduction The European Union Aviation Safety Agency (EASA) mandates comprehensive management of information security risks in aviation to safeguard operations,…

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.