Quick pick

SSDLC

SSDLC

18 posts
ISO 27001

ISO 27001

19 posts
TISAX

TISAX

9 posts
Security

Security

163 posts
AI & ML Article ECS Educational SSDLC

Introduction to the Secure SDLC in the AI-Native world: the reality check

Introduction This is the very first article from a series of articles that will be merged with the existing SDLC Process “From Idea to Proof of Concept to MVP” previously written, finally to be rewritten in an AI-Native SDLC.   What is an “AI-Native” organization? “AI-Native” describes an organization that has restructured how it works […]

CRA Cybersecurity ECS Educational General News

Cyber Resilience Act Single Reporting Platform (CRA-SRP) obligations for software companies selling globally

I wrote here about the CRA and the deployment plan: https://www.sorinmustaca.com/eu-cyber-resilience-act-cra-overview/  We are past September 11th and the Art. 14 of CRA is applying. Who is affected? Is a a company from a non EU country, which sells software globally affected by the CRA Art. 14? Any company is affected if the software is made […]

Article CSSLP ECS Educational Security SSDLC

Why SSDLC is helping shipping faster and more secure code

Software Delivered the Same Way Every Time Before security enters the picture, SDLC exists to solve a simpler problem: making software delivery repeatable. A team that builds features ad hoc, without a defined sequence of requirements, design, coding, testing, and release, ends up with wildly inconsistent outcomes — some releases solid, others full of regressions, […]

Article Certification Cybersecurity ECS Educational Security TISAX

ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance

This is the part 5 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance   Chapter 6 — Supplier Relationships This chapter addresses how the organization manages information security risks arising […]

Article Certification Cybersecurity ECS Educational Security TISAX

ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management

This is the part 3 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management Chapter 2 — Human Resources This chapter addresses the people dimension of […]

Article Cybersecurity ECS Educational News Security TISAX

ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization

This is the part 2 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization   Chapter 1 — IS Policies and Organization This chapter establishes the governance foundation of the […]