build Role playbook · MRO

Maintenance (MRO)

Engineers applying cyber-maintenance bulletins, patches and software-inventory hygiene on aircraft systems.

Audience: Maintenance, Repair & OperationsTime to first value: first patch cycle (1–2 weeks)

Why CyViation matters in your role

You already manage SBs, ADs and a maintenance calendar. CyViation adds the cyber side of the same airframe lifecycle:

No new tracker to learn — cyber maintenance fits your existing flow and approvers.

wb_sunnyDaily playbook

  1. Triage new vulnerability tickets for your fleet — confirm affected tails, severity, patch availability.
    [SkyRay → Vulnerability Management Dashboard]
  2. Verify overnight patch rollouts completed cleanly; anything degraded goes straight to the duty manager.
    [Vulnerability UI → Patch Calendar]
  3. Check tonight's maintenance window calendar — confirm each deployment has a tail on stand and a qualified engineer.
  4. Acknowledge cyber-maintenance bulletins (CMBs) as they land — same rhythm as SBs/ADs.
  5. Close out yesterday's tickets with the artefact attached (patch manifest, post-patch test, SBOM diff).

event_repeatWeekly playbook

  1. Update the SBOM per tail — reconcile any new components added during the week.
  2. Run a vulnerability-server scan report per tail and per fleet; trend exposure, don't just chase point-in-time CVEs.
  3. Review parked-aircraft exposure — stored / AOG tails accumulate debt and get missed.
  4. Coordinate with the CISO on out-of-cycle patches that can't wait for the next window.
  5. Sync with the MRO of another shift so handover stays consistent.

checklistFirst 30 days

grid_viewKey screens

Use caseScreen
Vulnerability backlog for my fleetCompliance Dashboard · [SkyRay → Vulnerability Management]
Per-tail cyber-maintenance status[SkyRay → Aircraft Asset View]
Plan / track patch windows[Vulnerability UI → Patch Calendar]
External advisory feed[Overwatch → CISA / Avionics Advisory Feed]
Software bill-of-materials per tail[SkyRay → Aircraft Asset View → SBOM tab]

priority_highWhen to escalate

SituationWhoHow
Critical CVE, no patch, fleet exposureCISO + Fleet ManagerSame call you'd make for a critical SB
Patch rollout failed; aircraft now degradedDuty manager + SOC on-callAvailability impact, not a cyber call alone
Tail repeatedly shows the same exposureCISOArchitectural, not maintenance
Vendor advisory contradicts CyViation guidanceCyViation TAM + CISODon't pick a side alone

menu_bookGlossary

Full list on the Glossary page. Key terms here: CMB, SBOM, CVE, out-of-cycle patch, risk acceptance.