top of page
All Posts
EASA Part-IS: How to Tell the Difference Between a Vulnerability and an Incident (And Why You Must)
Understanding the distinction between vulnerabilities and incidents is critical for effective EASA Part-IS compliance. This article provides a clear, practical breakdown of IS.I.OR.220, helping organisations correctly assess, manage, and respond to each. It offers structured guidance to strengthen your ISMS, support informed decision-making, and ensure a proactive, risk-based approach to aviation information security.

Luka Pace Bonello
4 days ago6 min read
Â
Â


How to Reduce Information Security Risk Under EASA Part-IS
Reducing information security risk under EASA Part-IS goes beyond theory. This article explains how aviation organisations can apply risk treatment in practice, using a real flight operations example. Learn how to reduce risk levels through targeted security controls, structured decision-making, and a practical risk treatment plan aligned with Part-IS requirements.

Luka Pace Bonello
Mar 267 min read
Â
Â


Information Security Risk Treatment under EASA Part-IS: A Practical Guide
How should aviation organisations treat information security risks under EASA Part-IS? This article explains how unacceptable cyber risks should be reduced, documented, and managed in practice under IS.I.OR.210. Using a realistic flight operations example, it shows how aviation organisations move from risk identification to effective risk treatment while protecting aviation safety.

Luka Pace Bonello
Mar 136 min read
Â
Â


How to Assess Information Security Risks Under EASA Part-IS: A Practical Safety-Focused Approach
Assessing information security risks under EASA Part-IS requires more than technical analysis. It demands a structured, safety-focused approach that identifies how compromised information could affect safe operations. Using a practical CAMO maintenance data scenario, this article breaks down how to evaluate impact, reason through likelihood, derive risk, and ensure assessments are aligned with aviation safety principles.

Luka Pace Bonello
Feb 266 min read
Â
Â


EASA Part-IS Risk Assessments Explained: Protecting Aviation Safety in the Digital Age
Information security risk assessment under EASA Part-IS transforms information security from a technical concern into a core aviation safety function. By identifying threat scenarios, assessing safety impact, and evaluating likelihood, organisations can understand where digital risks may affect safe operations and ensure protective measures are focused where they matter most.

Luka Pace Bonello
Feb 175 min read
Â
Â


bottom of page