top of page


Responding to Information Security Vulnerabilities Under EASA Part-IS (IS.I.OR.220)
Not every vulnerability needs fixing. But every one of them needs a decision. Under IS.I.OR.220, the act of logging a weakness and setting it aside is itself a risk position — and it needs to be a deliberate one. This article covers how vulnerability response should actually work: CVSS scoring, contextual risk assessment, and when treatment becomes mandatory under EASA Part-IS.

Luka Pace Bonello
Jun 145 min read


How to Assess Information Security Risks Under EASA Part-IS: A Practical Safety-Focused Approach
Assessing information security risks under EASA Part-IS requires more than technical analysis. It demands a structured, safety-focused approach that identifies how compromised information could affect safe operations. Using a practical CAMO maintenance data scenario, this article breaks down how to evaluate impact, reason through likelihood, derive risk, and ensure assessments are aligned with aviation safety principles.

Luka Pace Bonello
Feb 266 min read


EASA Part-IS Risk Assessments Explained: Protecting Aviation Safety in the Digital Age
Information security risk assessment under EASA Part-IS transforms information security from a technical concern into a core aviation safety function. By identifying threat scenarios, assessing safety impact, and evaluating likelihood, organisations can understand where digital risks may affect safe operations and ensure protective measures are focused where they matter most.

Luka Pace Bonello
Feb 175 min read


How to Define Your ISMS Scope Under EASA Part-IS
Defining an ISMS scope under EASA Part-IS requires more than identifying systems or organisational boundaries. It demands a safety-focused understanding of how information supports approved aviation activities and where information security risks could affect safety. This article explores a structured, practical approach to defining ISMS scope that aligns operational reality with Part-IS regulatory expectations.

Luka Pace Bonello
Jan 146 min read


What an ISMS Scope under EASA Part-IS Is
ISMS scoping under Part IS is about protecting aviation safety, not everything at once.
Discover how to define a clear, defensible ISMS scope by focusing on aviation safety elements exposed to information security risks, and why getting this step right makes Part IS compliance far easier.

Luka Pace Bonello
Jan 74 min read
bottom of page