top of page


Responding to Information Security Vulnerabilities Under EASA Part-IS (IS.I.OR.220)
Not every vulnerability needs fixing. But every one of them needs a decision. Under IS.I.OR.220, the act of logging a weakness and setting it aside is itself a risk position — and it needs to be a deliberate one. This article covers how vulnerability response should actually work: CVSS scoring, contextual risk assessment, and when treatment becomes mandatory under EASA Part-IS.

Luka Pace Bonello
Jun 145 min read


How to Detect Incidents and Vulnerabilities Under EASA Part-IS (IS.I.OR.220)
Incident and vulnerability detection under EASA Part-IS begins with the collection and analysis of information security events. This article explains how monitoring, internal reporting, external intelligence, and auditing work together to identify abnormal activity, detect incidents early, and uncover vulnerabilities that may impact aviation safety and operational integrity.

Luka Pace Bonello
May 86 min read


EASA Part-IS: How to Tell the Difference Between a Vulnerability and an Incident (And Why You Must)
Understanding the distinction between vulnerabilities and incidents is critical for effective EASA Part-IS compliance. This article provides a clear, practical breakdown of IS.I.OR.220, helping organisations correctly assess, manage, and respond to each. It offers structured guidance to strengthen your ISMS, support informed decision-making, and ensure a proactive, risk-based approach to aviation information security.

Luka Pace Bonello
Apr 106 min read
bottom of page