<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Posts on BLACK MONKEY Security GmbH - Find out more about us!</title>
        <link>https://bm-sec.de/en/posts/</link>
        <description>Recent content in Posts on BLACK MONKEY Security GmbH - Find out more about us!</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en-US</language>
        <lastBuildDate>Thu, 06 Nov 2025 10:23:41 +0100</lastBuildDate>
        <atom:link href="https://bm-sec.de/en/posts/index.xml" rel="self" type="application/rss+xml" />
        
        <item>
            <title>Certification by Kassenärztliche Bundesvereinigung</title>
            <link>https://bm-sec.de/en/posts/20251106/kbvcert/</link>
            <pubDate>Thu, 06 Nov 2025 10:23:41 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20251106/kbvcert/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20251106/kbvcert.png&#34;  alt=&#34;picture physician&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Certification in accordance with Section 390 of the German Social Code, Book V (SGB V) by &amp;ldquo;Kassenärztliche Bundesvereinigung&amp;rdquo; (KBV, &amp;ldquo;National Association of Statutory Health Insurance Physicians&amp;rdquo;) has been successfully completed.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20251106/kbvcert.png"  alt="picture physician"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>Certification in accordance with Section 390 of the German Social Code, Book V (SGB V) by &ldquo;Kassenärztliche Bundesvereinigung&rdquo; (KBV, &ldquo;National Association of Statutory Health Insurance Physicians&rdquo;) has been successfully completed.</p>
<p>The KBV&rsquo;s personal certification is initially valid for three years and can be extended thereafter.</p>
<p>The KBV&rsquo;s IT security guideline provides responsible practice owners with a reliable framework and guidance on what needs to be implemented in their practice in terms of IT security. The guideline specifies graduated requirement profiles for medical practices of different sizes and with different equipment. These range from sets of requirements for small practices to somewhat more complex sets of requirements for large medical care centers. In addition, separate requirements for large medical devices and requirements for decentralized components of the (national) telematics infrastructure are available, depending on their applicability in the respective context.</p>
<p>We are thus becoming a service provider that has been specifically certified with regard to the implementation of the requirements of the KBV&rsquo;s IT security guideline.</p>
<p>Further information can be found on the KBV website.</p>]]></content>
        </item>
        
        <item>
            <title>Qualification IT-Grundschutz-Praktiker (BSI)</title>
            <link>https://bm-sec.de/en/posts/20251024/itgspraktiker/</link>
            <pubDate>Fri, 24 Oct 2025 10:54:27 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20251024/itgspraktiker/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20251024/itgspraktiker.png&#34;  alt=&#34;Picture reading&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After passing the exam, we welcome a new IT-Grundschutz-Praktiker (BSI) to the organization.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20251024/itgspraktiker.png"  alt="Picture reading"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>After passing the exam, we welcome a new IT-Grundschutz-Praktiker (BSI) to the organization.</p>
<p>The personal certification of the Federal Office for Information Security (BSI, Bundesamt für Sicherheit in der Informationstechnik) focuses on the current BSI standards (200-x). In addition, some knowledge of the application and structure of the IT baseline protection compendium is advantageous.</p>
<p>The course teaches basic knowledge of the IT-Grundschutz methodology, business continuity management (BSI standard 200-4), and certification according to BSI standards (&ldquo;ISO 27001 certification based on IT-Grundschutz&rdquo;).</p>
<p><em>This certificate is mostly relevant in the context of the German information security context and the relevant German standards.</em></p>]]></content>
        </item>
        
        <item>
            <title>NIS-2: Something New and Old</title>
            <link>https://bm-sec.de/en/posts/20250927/nis2implement/</link>
            <pubDate>Sat, 27 Sep 2025 10:23:16 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250927/nis2implement/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250927/nis2implement.png&#34;  alt=&#34;Bild glasses and a book&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The implementation of NIS-2 into national law is still pending in Germany.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250927/nis2implement.png"  alt="Bild glasses and a book"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>The implementation of NIS-2 into national law is still pending in Germany.</p>
<p>From the EU&rsquo;s perspective, all member states should have implemented the “NIS-2 Directive” into their national law long ago. Official information on this subject is primarily available from Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security, &ldquo;BSI&rdquo;).</p>
<h1 id="news-from-the-eu">News from the EU</h1>
<p>The European Union Agency for Cybersecurity (ENISA) recently published another document related to NIS-2: “NIS2 Technical Implementation Guidance.” Anyone who would like to start looking at specific implementations for NIS-2 in Germany should take a look at this document.</p>
<p>Although there may still be changes to the requirements on the national side as the legislation is transposed into German law, it can be assumed that the basic content and concepts (which are being developed at EU level for NIS-2) will essentially remain the same at the national level. The new EU document deals in particular with methodological requirements for achieving compliance with “NIS-2.”</p>
<h2 id="contents-of-the-enisa-document">Contents of the ENISA document</h2>
<p>In addition to scope limitations, the document contains explanations of the following technical and methodological requirements:</p>
<ul>
<li>Network and information system security policy,</li>
<li>Risk management policy,</li>
<li>Incident handling,</li>
<li>Business continuity and crisis management,</li>
<li>Supply chain security,</li>
<li>Security in the procurement, development, and maintenance of network and information systems,</li>
<li>Guidelines and procedures for assessing the effectiveness of cybersecurity risk management measures,</li>
<li>Basic cyber hygiene practices and security training,</li>
<li>Cryptography,</li>
<li>Human resources security,</li>
<li>Access control,</li>
<li>Asset management and</li>
<li>Physical and environmental security.</li>
</ul>
<h1 id="what-stands-out">What stands out?</h1>
<p>If you take a closer look at the document content and have already dealt with standards and frameworks for information security in advance, you will also recognize the “high-level” requirements for an information security management system (ISMS) here.</p>
<p>NIS-2 cannot be viewed as a “pure IT problem” either, but rather describes a task for all areas of an organization. Of course, it can be made a pure “IT problem” if, for example, the supply of electricity for IT devices, the hiring of IT personnel, the procurement of IT devices, etc. are fully shifted to IT. This would eliminate the need for building management department, human resources department, or purchasing department within the organization, as they would have become redundant in the context of the “expanded IT department.”</p>
<p>But joking and irony aside, information security and its holistic management remain a comprehensive task for the institutions and organizations concerned.</p>
<h1 id="impact-on-organizations">Impact on organizations</h1>
<p>Of course, there is no such thing as complete, “100%” cyber-secure organization. But with a good starting point, requirements for achieving an acceptable level of security can be implemented without impossibly high costs. Some companies become part of a supply chain that imposes cybersecurity requirements on them, while other organizations may be subject to regulation (in Germany: “NIS-2” or “KRITIS”). The most favorable starting point is, of course, to address the issue of cybersecurity on your own initiative.</p>
<h2 id="who-has-an-easier-time-implementing-it">Who has an easier time implementing it?</h2>
<p>Organizations that have already established an ISMS will find it easier to implement the requirements imposed on them by NIS-2. In many cases, the requirements of NIS-2 will first be mapped onto existing and implemented requirements of the already established ISMS in order to identify possible gaps or “blind spots.” It is likely that compliance with NIS-2 can be achieved with few changes to the existing ISMS.</p>
<p>If an ISMS has not yet been established, an established and well-functioning process management system and a corporate culture that can respond efficiently to change will be very helpful for organizations.</p>
<h2 id="what-might-the-first-steps-look-like">What might the first steps look like?</h2>
<p>“Many roads lead to Rome.” We recommend first creating an overarching document - often referred to as a ‘guideline’ or “information security policy document.” If you manage this step well, sensitize stakeholders, and “get them on board from the start,” you will have a starting point for all further processes involved in establishing an ISMS.</p>
<p>The next step is to implement risk management. This often consists of describing a procedure and ultimately mapping out the risk management process. This “mapping” often takes the form of a data collection or list of identified risks that are addressed after identification. Perhaps your organization already has a risk management system in place that can be expanded to include information security.</p>
<h1 id="conclusion">Conclusion</h1>
<p><strong>Getting started is important!</strong></p>
<p>NIS-2 gives greater importance to governance at the corporate management level and awareness as a management responsibility. NIS-2 will sensitize some corporate management teams not only to the topic of counter-espionage (“Where do I store my sensitive information?”) but also to potential liability risks.</p>
<p>However, waiting for the NIS-2 Directive to be transposed into national law in Germany means losing valuable time. Resource bottlenecks already exist today, especially if you need to acquire skills and expertise within your organization or want to purchase additional resources from service providers.</p>
<p>The reason is obvious. First, you need to know and be able to implement the “state of the art”; second, regulation in the field of cybersecurity is constantly increasing; and third, the technical and organizational landscape is constantly evolving. Remote working has become increasingly prevalent in recent years, and blockchain, cloud, artificial intelligence, zero-trust concepts, and quantum-secure cryptography are hot topics. Experts in these complex fields are therefore somewhat scarce.</p>]]></content>
        </item>
        
        <item>
            <title>ISMS tools and software support</title>
            <link>https://bm-sec.de/en/posts/20250825/ismstool/</link>
            <pubDate>Mon, 25 Aug 2025 11:48:31 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250825/ismstool/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250825/ismstool.png&#34;  alt=&#34;Bild Worker with wrench&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;How can an information security management system (ISMS) be supported or even implemented with the help of tools?&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250825/ismstool.png"  alt="Bild Worker with wrench"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>How can an information security management system (ISMS) be supported or even implemented with the help of tools?</p>
<h1 id="variants">Variants</h1>
<p>The basic understanding is that an ISMS is not primarily a piece of software or a complete application, but rather a formless management system. In other words, it is a system consisting of - in abstract terms - tools and methods for managing information security.</p>
<h2 id="the-usual-start">The usual start</h2>
<p>The first tools used to establish and initially operate an ISMS are usually documents (guidelines, policies, process documents, etc.) and lists (inventories, etc.). Nowadays, this is no longer done by hand, but with the help of word processing programs and spreadsheet software.</p>
<p>Existing office applications on workstations are often the first software tools used to implement an ISMS.</p>
<h2 id="specialized-software">Specialized software</h2>
<p>In the context of information security, there are various types of specialized applications for managing the information and data necessary to meet the requirements of an ISMS. The transition between “automated” spreadsheet templates and standalone applications is not always clearly defined. As a rule, specialized software supports one or more information security norms or standards.</p>
<p>Various functions required for an ISMS may be integrated into these software solutions - for example, document version management or a simple solution for risk inventory. As you might imagine, existing solutions (software for document management systems, risk management systems, quality management systems, ticket systems, etc.) have been expanded by manufacturers to also support information security management. Software for an ISMS has therefore not always been developed with the primary goal of focusing on information security. Some software was originally designed to meet other requirements and purposes and has only been expanded to include information security as the need arose.</p>
<h2 id="generalized-compliance-applications">Generalized compliance applications</h2>
<p>There are quite extensive and powerful software solutions available within the framework of overarching “governance, risk, and compliance.” Within these applications, multiple management systems can be bundled into a holistic, integrated compliance system tailored to an organization. Quite often, various frameworks can be stored and manipulated in the form of management system requirements within these software systems. Many products ensure that synergies between different management systems (information security, data protection, quality, occupational safety, environmental management, etc.) can be exploited and that multiple entries of redundant data are avoided.</p>
<p>Another aspect of these application systems is the ability to exchange information with various other systems via interfaces. This means that information in these compliance systems does not have to be compiled manually, but can be automatically transferred from other systems. This helps to keep the information up to date and eliminates redundant entries by different organizational units within a company. This is not an exclusive feature of these complex software applications, but in these applications, the ability to flexibly set up interfaces to other systems is usually very pronounced.</p>
<p>Usually such systems are also highly adaptable to the company&rsquo;s own requirements. Modern systems often offer flexible configuration options, so that complex programming is not necessary for every change to the system.</p>
<h1 id="conclusion">Conclusion</h1>
<p>The transitions between the various “sizes” of software applications mentioned above are fluid. The easier it is to integrate supporting software into the organization, the easier it will be to gather the necessary information from the organization into the tool-supported ISMS. The design of a software program is only one facet of success. Another important aspect is the acceptance of the tool by the organization&rsquo;s employees or by those stakeholders who have to contribute information to the ISMS as part of their duties.</p>
<p>The reduction and avoidance of redundancies, the use of synergy effects from existing information collections, and the bundling of this information into one or more ISMS tools reduce recurring work and enable the often scarce resources of information security to be used for conceptual work, the integration of new assets, and increasing the maturity level of the ISMS.</p>]]></content>
        </item>
        
        <item>
            <title>From information security incidents to emergencies</title>
            <link>https://bm-sec.de/en/posts/20250721/incident/</link>
            <pubDate>Mon, 21 Jul 2025 19:31:28 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250721/incident/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250721/incident.png&#34;  alt=&#34;Bild saviour&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;An important component of information security management systems (ISMS) is the identification and management of information security incidents.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250721/incident.png"  alt="Bild saviour"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>An important component of information security management systems (ISMS) is the identification and management of information security incidents.</p>
<p>On the one hand, all impairments to the management system are tracked and dealt with in a structured manner as part of incident management and, on the other hand, the analysis of incidents can often be used to better adapt or improve the management system. Continuous improvement of the ISMS is usually also a requirement of management systems per se.</p>
<p>In particular, root cause analyzes of events can be incorporated into risk management or result in the adaptation of guidelines or processes. As soon as an ISMS has reached a certain level of maturity or external requirements have to be fulfilled explicitly, a distinction should be made between different types of events.</p>
<h1 id="attempt-at-classification">Attempt at classification</h1>
<p>Various classes of events can be defined. As soon as the management systems reach a certain level of complexity or there is a correspondingly high occurrence of events, events should be categorized into levels or &ldquo;criticalities&rdquo;. For example, a classification based on the level of impact could be used. <em>Please bear in mind that a classification of events must be adapted to the respective organization and its individual requirements.</em></p>
<h2 id="events">Events</h2>
<p>Information security events are often the lowest-threshold class of events. Business processes are affected negligibly or only very slightly.</p>
<h2 id="incidents">Incidents</h2>
<p>Incidents are events whose impact on business processes has reached such an extent that structured handling and root cause analysis is required. Some incidents contain a time-relevant component - without prompt handling, they can escalate further and possibly become a threat to business operations.</p>
<h2 id="incidents-to-be-reported">Incidents to be reported</h2>
<p>Incidents with an obligation to be reported are incidents whose impact or impairment of business processes is so severe and extensive that a reporting obligation is triggered. This reporting obligation can, for example, result from contractual agreements if your own organization is part of a supply chain. There may also be an obligation to report to a higher-level group structure or to supervisory authorities. In Germany, for example, there is currently an obligation to report to the relevant office of the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik - BSI) in the context of critical infrastructures.</p>
<h2 id="emergencies">Emergencies</h2>
<p>It can happen that the transitions from serious incidents to emergencies are fluid. It is therefore advisable to link incident and event management from the ISMS with the BCMS (Business Continuity Management System). With a good interface between the two management systems, a transition can be made with the least possible loss of time so that emergency plans can be put into action as quickly as possible and the effects of emergencies can be contained as quickly as possible. Emergencies usually mean that critical business processes have been catastrophically disrupted and business operations have come to a standstill, at least in part.</p>
<h1 id="notes">Notes</h1>
<p>When setting up and operating an ISMS, it also makes sense to analyze the requirements of the organization and adapt the management of events in the ISMS when classifying events. If management of IT events or data protection events exists in an organization, these should be analyzed when designing the information security event management.</p>
<p>As part of continuous improvement, changes to the event management processes of organizational units should also be continuously considered over time and integrated into the incident management of the ISMS if necessary.</p>]]></content>
        </item>
        
        <item>
            <title>Further offers for small and medium enterprises</title>
            <link>https://bm-sec.de/en/posts/20250603/transfer/</link>
            <pubDate>Tue, 03 Jun 2025 05:57:31 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250603/transfer/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250603/transfer.png&#34;  alt=&#34;picture liftign weight&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Last month, we were able to expand our portfolio with a particular focus on small and medium-sized enterprises.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250603/transfer.png"  alt="picture liftign weight"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>Last month, we were able to expand our portfolio with a particular focus on small and medium-sized enterprises.</p>
<h1 id="project-transferstelle-cybersicherheit">Project &ldquo;Transferstelle Cybersicherheit&rdquo;</h1>
<p>The federal project &ldquo;Transferstelle Cybersicherheit&rdquo; offers its services free of charge. The focus is on small and medium-sized enterprises, start-ups and craft businesses. The transfer office is funded by the Federal Ministry for Economic Affairs and Climate Protection.</p>
<p>In addition to various materials, a range of events are offered on the website. These events often deal with the targeted development of expertise and knowledge. However, you can also find dates for specialist conferences. Various topics from the field of “cyber security” are represented. These include classics such as “ISMS”, “data protection” and “backup”, as well as current topics such as “artificial intelligence” and its secure use or “NIS2”. Participation is possible online in many cases.</p>
<p>Last month, we pursued two projects together with Transferstelle Cybersicherheit:</p>
<ul>
<li>Providing our expertise as part of the emergency assistance offer</li>
<li>Qualification as an IT security trainer</li>
</ul>
<h2 id="emergency-assistance">Emergency assistance</h2>
<p>A special part of the &ldquo;Transferstelle Cybersicherheit&rsquo;s&rdquo; offer is “emergency assistance”. Here, affected companies can receive initial general recommendations for action on possible IT security incidents as well as support from experts. It is therefore a reactive offer for the worst case scenario: “A day late and a dollar short.” This service also offers an initial assessment of your own situation.</p>
<p>In our view, this is a very simple way to get help if your own company has been caught unprepared and is often in “headless chicken” mode in practice. At this point, prepared companies find it easier to implement the so-called “incident response” on their own and to cope with potentially catastrophic operational disruptions on their own using prepared emergency plans.</p>
<h2 id="qualification-it-security-trainer">Qualification IT security trainer</h2>
<p>We were also able to gain further qualifications with the help of the “mIT Sicherheit Ausbilden” sub-project of the Transferstelle Cybersicherheit. The aim of this qualification is to support those responsible for training with tailored information, suggested methods and learning materials on the topic of IT security. The secure use of information technology must become part of the skills of employees as early as possible. It therefore makes sense to provide the “employees of the future” with appropriate modules as part of their early training.</p>
<p>In this context, we can also support companies in sensitizing their trainees and employees to information security. Our offer is flexible. On request, we can either act as a multiplier or directly offer topic-related training, awareness campaigns or trainee modules.</p>
<h1 id="our-assessment">Our assessment</h1>
<p>The cooperation with the Transferstelle Cybersicherheit has left us with a consistently positive impression. Dialogs with contact persons have been very pleasant and both the events offered and the coordination regarding our possible contributions to support small and medium enterprises have been constructive in every case.</p>
<p>We already had points of contact with the “mIT Standard sicher” project in 2024. A consulting standard was developed in this project, which can now be found as a &ldquo;CyberRisikoCheck&rdquo; (cyber risk check) in accordance with DIN SPEC 27076 on the BSI (German Federal Office for Information Security) website, among others. Up-to-date information on this can be found either on the BSI website or on the website of project Transferstelle Cybersicherheit. At the same time, interested companies can also find a guided self-assessment on the website of the Transferstelle Cybersicherheit. This self-assessment is somewhat lower-threshold than the &ldquo;CyberRiskoCheck&rdquo; in accordance with DIN SPEC 27076 or the &ldquo;Cyber-Sicherheits-Check&rdquo; from the &ldquo;Allianz für Cybersicherheit&rdquo;.</p>
<p>All in all, there are many offers for companies of all sizes to do something about their own information security. In our view, the most important thing is to set out and protect yourself. The more information technology is used and the more digital your own processes become, the more important it is to build up skills and expertise in these areas. If you don&rsquo;t have the time to build up resources internally, we will be happy to support you.</p>]]></content>
        </item>
        
        <item>
            <title>Cross-section &#34;cyber security&#34; for the first third of 2025</title>
            <link>https://bm-sec.de/en/posts/20250508/drittel-third/</link>
            <pubDate>Wed, 07 May 2025 08:14:53 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250508/drittel-third/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250508/first-third.png&#34;  alt=&#34;Picture with newspaper&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Let&amp;rsquo;s take a look at what has been going on in the first third of 2025 in the field of information security in a number of different organizations - both nationally and internationally.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250508/first-third.png"  alt="Picture with newspaper"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>Let&rsquo;s take a look at what has been going on in the first third of 2025 in the field of information security in a number of different organizations - both nationally and internationally.</p>
<h1 id="a-few-selected-organizations">A few selected organizations</h1>
<p>First, we look at the publications of some organizations from the beginning of the year to around the end of April 2025. At this point, we would like to point out that this is not a complete and comprehensive survey of all publications. We simply want to give a brief overview of what we found interesting. Press releases on organizational changes or announcements of an “open day” were excluded for this article.</p>
<h2 id="bsi">BSI</h2>
<p>The <em>Bundesamt für Sicherheit in der Informationstenik</em> is a German federal authority and deals with information security and digitization issues for public institutions, commercial enterprises and private individuals.</p>
<p>Some of you may be familiar with the annual report on the state of IT security in Germany. For example, we look at BSI publications and press releases irregularly throughout the year. This is also due to the localization of KRITIS tasks within their organization and the still current NIS2 topic with effects on many national organizations and companies - i.e. customers or potential customers of ours.</p>
<p>At the Munich Security Conference, the BSI contributed to the topic of AI and its potential influence on democracy. In the wake of Crowdstrike in connection with Microsoft operating systems, the BSI took action and investigated the incident. Drones have come under scrutiny as a cyber threat - in principle, research and development is currently being stepped up in this area to make these technologies usable in a wide variety of forms. A fairly central “technical guideline” on crypto procedures was updated with regard to post-quantum cryptography and, in addition to the suggestion of regular data backups against the backdrop of “World Backup Day”, tailored offers for cyber security topics were made to the target group as part of the German Senior Citizens&rsquo; Day.</p>
<p>No issue of the biannual BSI magazine has yet been published in 2025. This year&rsquo;s Cyber Security Day will take place in the middle of the month - an agenda of content will be provided. We are particularly looking forward to NIS2 news. Together with ZenDIS (“Center for Digital Sovereignty in Public Administration”), the BSI has published a strategy paper for “Secure Software Supply Chains” (refers to software supply chains in public administration). A new version of the guidance for “KRITIS verification procedure” (essentially terms for auditing KRITIS-compliance) was published, as was a working aid on the “Secure software lifecycle”. In addition, basic protection profiles for small/medium airports and public road passenger transport (subway, streetcars, buses, etc.) were published. A document on opportunities and risks in the context of generative AI models was also updated. Final documentation on the SIKIS project (“Security features of hospital information systems”) has been made available. In the context of (KRITIS) verifications, a document for maturity and implementation level assessment was also published.</p>
<h2 id="ncsc">NCSC</h2>
<p>The <em>National Cyber Security Centre</em> is an organization of the United Kingdom with the purpose of advising and supporting the public and private sector. The aim is to prevent cyber security threats.</p>
<p>A research paper on reducing “unforgivable” errors was published, strategies for migrating to post-quantum cryptography were presented, new regulations for critical sectors were announced, new guidelines for securing edge devices were published, information for high-risk groups at risk of digital surveillance was compiled and risks for critical systems in relation to emerging AI threats were outlined.</p>
<h2 id="enisa">ENISA</h2>
<p>The <em>European Network and Information Security Agency</em> of the European Union is concerned with achieving a high level of cyber security. Its purpose is to strengthen the ability to defend against cyber-attacks and to increase confidence in cyber security with the aim of ensuring the smooth functioning of the internal market.</p>
<p>At the beginning of the year, ENISA published its work program for 2025-2027. Prominent topics in this document are the Cybersecurity Act and the NIS2 directive. The threat landscape in the financial sector, the maturity assessment of critical sectors and the threat landscape in space (in particular satellites) were also addressed.</p>
<h2 id="cisa">CISA</h2>
<p>The American <em>Cybersecurity and Infrastructure Security Agency</em> is responsible for protecting the various levels within the American administration.</p>
<p>CISA started the year with a report regarding a cyber security incident in the treasury department. They also dealt with publications about the security posture of schools. Reports on meetings of SAFECOM (emergency responders and elected representatives from various levels of government) and NCSWIC (coordination for cooperation between the individual states) were published. A press release on CISA&rsquo;s own Red Team was issued. Awareness was raised regarding the resilience of integrated information and communication supply chains. A joint warning with the NSA regarding the use of “fast flux” networks by attackers was published and various clarifying information relating to the CVE (Common Vulnerabilities and Exposures) program was provided.</p>
<h2 id="nist">NIST</h2>
<p>The American <em>National Institute of Standards and Technology</em> deals with standardization processes, among other things. At this point, the NIST is the publisher of various cyber security standards relevant to the USA.</p>
<p>A reference profile (also available in German) for consumer IoT products has been published. Supply chain security was also addressed here at the start of the year. Other topics included the future security of the Web3 paradigm and establishing a stronger link between business impact analyses and risk prioritization and response. A status report on the fourth round of the post-quantum cryptography standardization process can also be found. Work on CSF 2.0 (Cyber Security Framework) continues, in particular translations and incident response recommendations in the context of cyber security risk management. In addition, an annual report for the 2024 fiscal year can be found for the NIST Cybersecurity and Privacy Program.</p>
<h1 id="considerations--conclusion">Considerations / Conclusion</h1>
<p>In our view, there are overlaps in the topics considered by the various organizations. Post-quantum cryptography, protection of (critical) infrastructures and securing supply chains are current topics in national and supranational publications. At the same time, there are also differences in the focus of the various countries.</p>
<p>From our analysis, we can see that Germany is focusing on pushing ahead with the delayed implementation of content for regulated companies (KRITIS document updates and pushing ahead with the implementation of European NIS2 requirements at national level). In America - perhaps due to the current situation - the focus was on continuing the CVE program and commenting on its own resource situation (using the example of the CISA Red Team, among others).</p>
<p>Reading between the lines, one reads time and again about efforts to improve the links and interaction between the various stakeholders - both at national and international level. The EU stretches an umbrella over the individual member states of the economic area. But even within the individual states, the aim is to achieve the smoothest possible coordination between the individual countries and national authorities in order to drive forward cyber security issues.</p>
<p>At the end of the day, we believe it is worth taking a look at the publications of the organizations that directly affect you. But it also makes sense to think outside the box, as the various standards and norms used centrally in the individual economic areas are mutually beneficial. In the past, anyone who wanted to get to grips with the so-called “Zero Trust” paradigm at an early stage could read up extensively on the American standards. Many of the contents of the relevant NIST publications are nowadays also referenced in BSI publications when it comes to this topic.</p>]]></content>
        </item>
        
        <item>
            <title>What is meant by information security?</title>
            <link>https://bm-sec.de/en/posts/20250410/infosec-explained/</link>
            <pubDate>Thu, 10 Apr 2025 11:54:32 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250410/infosec-explained/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250410/infosec.png&#34;  alt=&#34;picture reading a book&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this article, we would like to explore the question of what can be understood by the term “information security”.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250410/infosec.png"  alt="picture reading a book"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>In this article, we would like to explore the question of what can be understood by the term “information security”.</p>
<p>In very abstract terms, information security describes the efforts to protect information by reducing, avoiding, transferring or accepting risks. Let us start with a fundamental question.</p>
<h1 id="what-is-information">What is information?</h1>
<p>A frequently used model is the so-called <strong>&ldquo;DIKW pyramid&rdquo;</strong>. DIKW stands for <strong>D</strong>ata, <strong>I</strong>nformation, <strong>K</strong>nowledge and <strong>W</strong>isdom.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>             _                     
</span></span><span style="display:flex;"><span>            / <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>           /   <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>          /     <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>         /       <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>        / wisdom  <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>       /___________<span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>      /  knowledge  <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>     /_______________<span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>    /   information   <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>   /___________________<span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  /        data         <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span> /_______________________<span style="color:#ae81ff">\
</span></span></span></code></pre></div><p>It is a model that describes how information can arise from data, knowledge can arise from information and wisdom can arise from knowledge.</p>
<p>Perhaps it is less abstract if you imagine a language as an example. Words can be formed from a set of characters, such as an alphabet. Data becomes information. These words can in turn be used to form sentences. Information becomes knowledge. Sentences can be turned into books, essays or poems. Knowledge becomes something “more” again. This “more” is described in the model as wisdom.</p>
<p>In everyday life, information can be complex data exchange procedures between two trading partners, notes on “scribbles” or a database with cooking recipes.</p>
<h1 id="where-is-information">Where is information?</h1>
<p>In the context of information security, the aim is to protect information. We now have an initial understanding of information. The next step is to find out where this information is located.</p>
<p>Over the course of time, we have changed from a society with few scribes and the associated few centralized recording locations to a society with a considerable number of people who read and write. Technology has also changed the means and methods of communication. In the past, records had to be pressed into clay tablets and today almost any amount of information in various forms (writing, sound, image) can be multiplied at the touch of a button and distributed across the entire planet at breakneck speed.</p>
<h2 id="the-digital-organization">The digital organization</h2>
<p>Information can be found in electronic and physical form in various places within an organization. In the course of digitalization, information is now not only hidden in paper-based file folders but primarily in application systems - often referred to as “IT systems”, i.e. “<em>i</em>nformation <em>t</em>echnology systems”. Information can also be stored in the heads of employees or hidden implicitly in processes. Perhaps a certain sequence of activities is required in a process in order to achieve a correct result. If this process is not formally described, it is implicit information that is hidden in the ongoing process (“implicit process knowledge”).</p>
<p>Of course, the information in an organization is not only stored. It is collected, processed, disclosed to third parties, changed or even deleted. If you think about it, access to information, or rather the regulation of access to information, is very important for the protection of information. After all, not every person in an organization should have read or even write access to payroll information.</p>
<h1 id="what-is-information-security">What is information security?</h1>
<p>In essence, information security is about protecting the availability, confidentiality and integrity of information in an organization. The aim is to find out <em>what</em> information is located <em>where</em> in the organization and to what extent risks exist with regard to this information. These risks must be assessed and dealt with. In most cases, measures will be taken to improve the protection of the information, i.e. to reduce the risks associated with the information to a manageable level.</p>
<p>Here, too, structured procedures for achieving this goal exist. You may be familiar with the ISO 27000 family of standards. These standards deal with management systems for information security.</p>]]></content>
        </item>
        
        <item>
            <title>We are part of the German Allianz für Cyber-Sicherheit</title>
            <link>https://bm-sec.de/en/posts/20250307/allianz-cybersec/</link>
            <pubDate>Fri, 07 Mar 2025 08:03:26 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250307/allianz-cybersec/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250307/allianz-cs.png&#34;  alt=&#34;picture club&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We have been part of the &amp;ldquo;Allianz für Cyber-Sicherheit&amp;rdquo; (alliance for cyber security, ACS) platform for a few weeks now.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250307/allianz-cs.png"  alt="picture club"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>We have been part of the &ldquo;Allianz für Cyber-Sicherheit&rdquo; (alliance for cyber security, ACS) platform for a few weeks now.</p>
<p>As part of this platform, we want to make our contribution to strengthening resilience to cyber attacks. We are currently one company out of 8,189 participants (as of March 7, 2025) with the common goal of shaping and strengthening cyber security in Germany.</p>
<p>In addition to the official pages of the &ldquo;Federal Office for Information Security&rdquo; (Bundesamt für Sicherheit in der Informationstechnik, BSI), the ACS website also offers information on various topics, such as management information for top level management or the implementation of the NIS-2 Directive. The procedure for transposing this directive into national law has not yet been completed (as originally planned).</p>]]></content>
        </item>
        
        <item>
            <title>What skills help a good CISO?</title>
            <link>https://bm-sec.de/en/posts/20250214/ciso-anatomy/</link>
            <pubDate>Fri, 14 Feb 2025 09:21:54 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250214/ciso-anatomy/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250214/skills.png&#34;  alt=&#34;picture penguin&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h1 id=&#34;various-skills&#34;&gt;Various skills&lt;/h1&gt;
&lt;p&gt;CISOs (Chief Information Security Officers) need a range of skills to be able to cover their area of responsibility effectively and efficiently.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250214/skills.png"  alt="picture penguin"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><h1 id="various-skills">Various skills</h1>
<p>CISOs (Chief Information Security Officers) need a range of skills to be able to cover their area of responsibility effectively and efficiently.</p>
<h2 id="understanding-of-the-company-or-the-organization">Understanding of the company or the organization</h2>
<p>Successful CISOs today must differentiate themselves from previous generations of CISOs by developing a good understanding of the organization, including goals, challenges, industry specifics and even competitors beyond the defined area of information security. Members of senior management or board members are expected to understand, question and contribute to every area of the organization (even if it is not directly part of their immediate area of responsibility). The situation should be analogous in the public sector, for example with departmental management.</p>
<p>A modern CISO must therefore actively put itself in a position to obtain this overall view - even if this is primarily done in the context of information security (“wear information security glasses”). CISOs who do not succeed in this will continue to be seen as highly technical specialists who report to a manager and whose statements can, at worst, be interpreted by decision-makers in a company as incomprehensible, technical statements.</p>
<p>Without an understanding of the comprehensive business activities of an organization, CISOs are unlikely to be recognized by top management and will likely not receive the necessary backing to perform their tasks. In order to develop these skills, a CISO must inevitably look beyond its own &ldquo;cybersecurity horizon&rdquo;.</p>
<h2 id="continuous-learning">Continuous learning</h2>
<p>Because information security risks and attack vectors are constantly changing, CISOs must demonstrate a continuous willingness to learn in order to adapt to new developments. Every good CISO spends a great deal of time understanding how currently known vulnerabilities intersect with the evolving threat landscape and how to continually improve the organization&rsquo;s security posture.</p>
<p>Information security is a constant game of cat and mouse that requires both strategic thinking and staying on top of the latest technology for sustained success.</p>
<p>Nowadays, it also involves keeping up to date with the numerous current and future regulations, directives, laws and rules on cyber security. A pure focus on technical innovations is a thing of the past. It is also necessary to keep pace with the ongoing technological change with regard to regulatory aspects.</p>
<h2 id="effective-communication">Effective communication</h2>
<p>The ability to communicate a “technical” topic effectively and accessibly to the various stakeholders is a key to success in information security. Conversely, it is equally important to be able to communicate “business” topics in a way that is understandable to technical professionals. Without developing the ability to communicate with different stakeholders in their “understandable language”, modern CISOs will rarely be successful.</p>
<p>CISOs develop, establish and manage complex information security programs that often impact all aspects of an organization. The communication required at this point encompasses all facets: from motivating and leading a dedicated team, to promoting a security-conscious culture throughout the organization, to effectively managing security incidents and crisis across many different organizational units.</p>
<p>Communication is required in all directions. Communication must take place with decision-makers regarding the release of required resources and the most informative language possible must be used with employees, for example to raise awareness of impending information security risks or to make abstract compliance requirements easier to understand. A good half of a CISO&rsquo;s work consists of communicating ideas, opportunities, concerns and plans to a large number of internal and external stakeholders.</p>
<p>If communication is not good, the concerns of information security are not understood and, in the worst case, the CISO is perceived solely as an annoying “naysayer”.</p>
<h2 id="nerves-of-steel">Nerves of steel</h2>
<p>Crisis management is commonplace in the position of an CISO. Dealing with incidents and managing security incidents is often already part of day-to-day business.</p>
<p>Employees of a company may also seek guidance from the CISO in the event of a crisis. For this reason, a CISO must be confident in their leadership approach and also exude confidence when developing a crisis response strategy and implementing it with employees in an organization.</p>
<p>Therefore, the ability to keep a cool head cannot be overemphasized. In particular, the current threat situation, in which entire organizations are sometimes permanently paralyzed by attacks (for example through encryption), places extensive demands on the personality and resilience of modern CISOs.</p>
<h2 id="prioritization-of-activities">Prioritization of activities</h2>
<p>CISOs or information security teams represent a cost centre in the organization. More often than one would like, in the CISO-role one will be forced to work with suboptimal budgets.</p>
<p>Prioritization of work ensures, up to a certain point, that a CISO is able to align a low-threshold investment program with business objectives, allocate resources effectively, prioritize the most important risks and meet the expectations of internal and external stakeholders to the extent possible.</p>
<p>If prioritization is poorly or even incorrectly done, this can in turn lead to reduced resource flows into information security projects, the overall information security management system, future reduced budgets, unnecessary negative impact on the organization and non-compliance with regulations. Ultimately, incorrect prioritization will result in wasted time.</p>
<p>You can estimate the cost of avoiding risks in advance, but you never know the actual cost of those risks. Especially things that don&rsquo;t happen are difficult to convert into tangible savings. This, too, can ultimately affect the budget of an CISO.</p>
<h2 id="technical-understanding">Technical understanding</h2>
<p>In most cases, an CISO does not need to be the most technically savvy member of an organization or the information security team. However, the role does require the ability to understand and evaluate current information security threats, defense mechanisms, defense techniques and emerging technologies. Otherwise, it will be difficult to make informed decisions, lead a team effectively and maintain your credibility as a CISO.</p>
<p>The technical protection of valuable company assets is of very high importance in the cyber security environment. It is crucial to have the right skills and knowledge for the role of CISO in this area as well. Otherwise, the CISO may find themselves at a loss in meetings and exposing the organization to avoidable risks.</p>
<h1 id="concluding-thought">Concluding thought</h1>
<p>The portfolio of skills and abilities of a CISO is diverse and must take into account the goal of continuous adaptation to changing circumstances. The points listed here are by no means meant to show the complete picture. They are merely intended to provide food for thought about the various challenges that a modern CISO must face.</p>]]></content>
        </item>
        
        <item>
            <title>Information security management: an IT-only issue?</title>
            <link>https://bm-sec.de/en/posts/20250128/topmanagementissue/</link>
            <pubDate>Tue, 28 Jan 2025 09:43:14 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250128/topmanagementissue/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250128/mgmtissue.png&#34;  alt=&#34;Bild card game&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In order to implement and manage information security appropriately, the entire organization must be considered with all of its elements required for value creation.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250128/mgmtissue.png"  alt="Bild card game"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>In order to implement and manage information security appropriately, the entire organization must be considered with all of its elements required for value creation.</p>
<p>A pure focus on information technology (IT) would overly abstract this task and obscure the actual complexity of the issue. In addition, this overly narrow view exposes the organization to all non-IT-related vulnerabilities without further consideration.</p>
<p>However, understanding information security has become a necessity in today&rsquo;s world, as the threats to information security are constantly changing. Their sophistication and frequency are increasing. Therefore, a holistic view of information security is required by organizations in order to establish effective information security management systems (ISMS). Information security cannot end at the boundaries of individual organizational units.</p>
<h1 id="three-various-factors">Three various factors</h1>
<p>Looking at international and national norms, standards and frameworks for information security, three key components can be identified that serve as the basic framework for grasping information security:</p>
<ul>
<li>people,</li>
<li>processes and</li>
<li>technologies.</li>
</ul>
<p>At an international level, the ISO 27000 family of standards should be mentioned. At national level, examples include the standards published in Germany by the &ldquo;Bundesamt für Sicherheit in der Informationstechnik&rdquo; (BSI) and the standards published in the USA by the National Institute of Standards and Technology (NIST).</p>
<h2 id="people">People</h2>
<p>It is sometimes easier to compromise a person than a technical system; at least if you assume that a technical system has been securely designed, configured and is subject to regular maintenance - here, too, people ultimately play the leading role.</p>
<p>Only when information security can be established as part of the organizational culture will it be possible to sustainably increase resistance to information security threats across all processes. An organizational culture is shaped and sustainably influenced in particular by managers and ultimately the top management level.</p>
<p>For example, every person in an organization can promptly submit an initial report in the event of an information security incident so that countermeasures can be initiated quickly.</p>
<h2 id="processes">Processes</h2>
<p>The running business processes are the necessary link between people and technology to operate the organization&rsquo;s value creation.</p>
<p>Analogous to the integration of information security into the organizational culture, information security must also be integrated into the process design when defining and possibly re-evaluating business processes. All organizational units are involved when it comes to information security. An HR department is responsible, among other things, for the information security of collected employee information, the procurement department is responsible, among other things, for information security in relation to the supply chains and the IT department is responsible, among other things, for information security in relation to the technology it uses.</p>
<p>For example: A referee who is also a member of a playing team will immediately spark discussion potential - at least among the opposing team. The process of selecting a referee for a match must be designed in such a way that the referee can or must be neutral in relation to the teams playing.</p>
<h2 id="technologies">Technologies</h2>
<p>The use of technology - especially information technology - is an important part of today&rsquo;s fast-paced world. However, as our technologies have become increasingly complex, they need to be evaluated in terms of their information security aspects, especially before and during their use.</p>
<p>For example, certain information in an organization is stored in such a way that not just anyone in the world can access it. In the past, this might have meant keeping a file in locked rooms or lockable cabinets and only sharing it with people within the physical site of an organization. Today, very large amounts of information can be duplicated by click on a button and at times is sent via wireless networks.</p>
<h1 id="summary">Summary</h1>
<p>People, processes and technologies must be considered “as a whole”. Responsibility for an organization “as a whole” does not normally lie within the IT department. This is why information security is not just an IT challenge. However, due to the permeation of business processes with information technology, an IT department will sometimes have to solve a larger proportion of issues in the context of information security than other organizational units.</p>
<p>Establishing and maintaining information security is a permanent task, as organizations (consisting of people + processes + technologies) are subject to constant change.</p>
<ul>
<li>People are changing their skills - hardly any business letters are still written by hand with ink on paper, nowadays people are more likely to enter characters and commands into applications.</li>
<li>Processes are adapted to technologies and people - letters are hardly ever transported with the help of horses and carriages anymore, so horseshoes or stables with water and hay are hardly needed in this area.</li>
<li>Technologies continue to develop - airplanes had to be invented for airmail and skills had to be acquired to operate them and navigate over longer distances.</li>
</ul>
<p>The management of information security and, in particular, the organization of this management is therefore initially the task of the top management level. Only in the next step does information security become the responsibility of the individual organizational units, including the IT departments.</p>]]></content>
        </item>
        
        <item>
            <title>Relaunch of the website</title>
            <link>https://bm-sec.de/en/posts/20250110/website-relaunch-25/</link>
            <pubDate>Fri, 10 Jan 2025 14:13:14 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20250110/website-relaunch-25/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20250110/relaunch.png&#34;  alt=&#34;Bild Rakete&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We are revamping our website at the start of the new year.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20250110/relaunch.png"  alt="Bild Rakete"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>We are revamping our website at the start of the new year.</p>
<p>The website is currently being converted to a new technological basis. In the course of this, we are also revising the content and multilingualism of our website. With the help of modern technologies - including artificial intelligence - we plan to have the conversion completed at the beginning of the next week.</p>]]></content>
        </item>
        
        <item>
            <title>PMP - Project Management Professional</title>
            <link>https://bm-sec.de/en/posts/20241220/pmp/</link>
            <pubDate>Fri, 20 Dec 2024 16:27:08 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20241220/pmp/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20241220/pmp.png&#34;  alt=&#34;picture sunglasses&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After passing the exam and successfully completing the application process, we welcome a new PMP (Project Management Professional) to the organization.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20241220/pmp.png"  alt="picture sunglasses"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>After passing the exam and successfully completing the application process, we welcome a new PMP (Project Management Professional) to the organization.</p>
<p>According to the Project Management Institute, there are over 1.4 million PMP-certified individuals worldwide. Obtaining this certification provides evidence of knowledge from the PMBOK Guide (A Guide to the Project Management Body of Knowledge) as well as transfer achievements from real day-to-day project work.</p>
<p>Once proof of relevant professional experience has been provided, continuous further training is now required in order to maintain the certification for the future.</p>]]></content>
        </item>
        
        <item>
            <title>The BSI CyberRisikoCheck</title>
            <link>https://bm-sec.de/en/posts/20241129/bsi-cyberriskocheck/</link>
            <pubDate>Fri, 29 Nov 2024 08:36:09 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20241129/bsi-cyberriskocheck/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20241129/CyberRisikoCheck_Logo.png&#34;  alt=&#34;BSI CyberRisikoCheck Logo&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After looking into the new DIN (Deutsches Institut für Normung) specification and taking part in a training event at the BSI (Bundesamt für Sicherheit in der Informationstechnik / German Federal Office for Information Security) for the use of the software to carry out the CyberRisikoCheck in accordance with DIN SPEC 27076 “IT-Sicherheitsberatung für Klein- und Kleinstunternehmen”, we are now pleased to be able to offer this check.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20241129/CyberRisikoCheck_Logo.png"  alt="BSI CyberRisikoCheck Logo"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>After looking into the new DIN (Deutsches Institut für Normung) specification and taking part in a training event at the BSI (Bundesamt für Sicherheit in der Informationstechnik / German Federal Office for Information Security) for the use of the software to carry out the CyberRisikoCheck in accordance with DIN SPEC 27076 “IT-Sicherheitsberatung für Klein- und Kleinstunternehmen”, we are now pleased to be able to offer this check.</p>
<h1 id="the-check-itself">The check itself</h1>
<p>This check consists of several steps, which can be roughly summarized as follows</p>
<ul>
<li>Initial meeting (basic procedure, required preparation on the customer side)</li>
<li>Carrying out the cyber risk check (answering the questions by the management and, if necessary, the IT manager role, resulting in a completed questionnaire and a risk status value)</li>
<li>Discussion of the result (explanation of the risk status value, recommendation for taking and prioritizing measures if necessary)</li>
</ul>
<p>There are currently a total of 27 questions from 6 fields of action that must be answered and evaluated. The use of the software provided by the Federal Office is not mandatory.</p>
<h1 id="further-information-on-the-cyberrisikocheck">Further information on the CyberRisikoCheck</h1>
<p>Additional information on the CyberRisikoCheck and available service providers can be found at the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik), for example.</p>
<h1 id="thinking-outside-the-box">Thinking “outside the box”</h1>
<p>Of course, we can also support you on the basis of other frameworks, norms and standards. In the field of information security, you may be familiar with ISO / IEC 27001, the BSI standards (200-x) or the industry-specific security standards (B3S) against the background of applicable KRITIS requirements at national level in Germany. In the area of business continuity management, ISO / IEC 22301 or the BSI standard 200-4 may be familiar.</p>]]></content>
        </item>
        
        <item>
            <title>Inspection procedure competence for § 8a BSIG</title>
            <link>https://bm-sec.de/en/posts/20231129/bsig-isaca/</link>
            <pubDate>Thu, 23 Nov 2023 16:32:25 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20231129/bsig-isaca/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20231129/bsig.png&#34;  alt=&#34;picture bauble&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After a thorough examination, we can add inspection procedure competence (&amp;ldquo;Prüfverfahrenskompetenz&amp;rdquo;) for § 8a BSIG (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik) to our organization.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20231129/bsig.png"  alt="picture bauble"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>After a thorough examination, we can add inspection procedure competence (&ldquo;Prüfverfahrenskompetenz&rdquo;) for § 8a BSIG (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik) to our organization.</p>
<p>This training was supported by ISACA Germany Chapter e.V., from whose American headquarters, among other things, the CISA certification originates.</p>
<p>With this additional qualification, knowledge of the special features of a KRITIS-specific audit in the area of § 8a BSIG can be acquired. Among other things, the following aspects are dealt with in this context:</p>
<ul>
<li>Assessment of the scope of application</li>
<li>Protection of security of supply with critical goods or services</li>
<li>Restrictions in the treatment of risks</li>
<li>Consideration of the “state of the art”</li>
<li>KRITIS-specific particularities</li>
</ul>
<p><em>Note: KRITIS describes “critical infrastructures” that are subject to separate regulation in Germany with regard to information security.</em></p>]]></content>
        </item>
        
        <item>
            <title>CISA - Certified Information Systems Auditor</title>
            <link>https://bm-sec.de/en/posts/20230831/cisa/</link>
            <pubDate>Thu, 31 Aug 2023 14:22:45 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20230831/cisa/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20230831/cisa.png&#34;  alt=&#34;picture ice&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After passing the exam and successfully completing the application process, we welcome a new CISA (Certified Information Systems Auditor) to the organization.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20230831/cisa.png"  alt="picture ice"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>After passing the exam and successfully completing the application process, we welcome a new CISA (Certified Information Systems Auditor) to the organization.</p>
<p>According to the Information Systems Audit and Control Association, there are over 151,000 CISA-certified individuals worldwide.</p>
<p>After providing proof of relevant professional experience, the next step is ongoing training to maintain the certification for the future.</p>]]></content>
        </item>
        
        <item>
            <title>CISSP - Certified Information Systems Security Professional</title>
            <link>https://bm-sec.de/en/posts/20230530/cissp/</link>
            <pubDate>Tue, 30 May 2023 12:41:19 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20230530/cissp/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20230530/cissp.png&#34;  alt=&#34;picture fire&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After passing the exam and successfully completing the application process, we welcome a new CISSP (Certified Information Systems Security Professional) to the organization.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20230530/cissp.png"  alt="picture fire"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>After passing the exam and successfully completing the application process, we welcome a new CISSP (Certified Information Systems Security Professional) to the organization.</p>
<p>According to the International Information System Security Certification Consortium, there were 152,632 CISSP-certified individuals worldwide at the start of 2022.</p>
<ul>
<li>in Germany 2,727</li>
<li>in Switzerland 1,087</li>
<li>in Austria 293</li>
</ul>
<p>After providing proof of relevant professional experience, continuous training will now be required to maintain certification for the future.</p>]]></content>
        </item>
        
        <item>
            <title>TÜV certification of persons</title>
            <link>https://bm-sec.de/en/posts/20220602/tuev-auditor/</link>
            <pubDate>Thu, 02 Jun 2022 11:04:56 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20220602/tuev-auditor/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20220602/auditor.png&#34;  alt=&#34;picture tuev&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;At this point, we would like to provide a brief overview of the personal certifications available in the organization from the TÜV Rheinland Academy portfolio.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20220602/auditor.png"  alt="picture tuev"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>At this point, we would like to provide a brief overview of the personal certifications available in the organization from the TÜV Rheinland Academy portfolio.</p>
<p>The following certifications have been obtained so far:</p>
<ul>
<li>08.05.2015: IT Security Officer (TÜV)</li>
<li>30.11.2016: IT Security Manager (TÜV)</li>
<li>13.12.2016: IT Security Auditor (TÜV)</li>
</ul>
<p>With the acquisition of the last of the three consecutive certificates of competence, you have extensive knowledge in the area of conformity requirements according to the native “ISO/IEC 27001” standard, conformity to “ISO/IEC 27001 based on IT-Grundschutz” and the audit process according to “ISO 19011”. They are also equipped to carry out internal audits within the organization and have acquired knowledge of the auditing procedures of accredited testing bodies for “ISO/IEC 27001” or “ISO/IEC 27001 based on IT-Grundschutz”.</p>
<p>In summary, these consecutive personal certifications provided knowledge about the establishment and operation of a standard-compliant information security management system (ISMS) as well as the preparation and implementation of an audit.</p>]]></content>
        </item>
        
        <item>
            <title>Founding of the company</title>
            <link>https://bm-sec.de/en/posts/20220504/gruendung-der-gesellschaft/</link>
            <pubDate>Mon, 04 May 2020 13:17:34 +0100</pubDate>
            
            <guid>https://bm-sec.de/en/posts/20220504/gruendung-der-gesellschaft/</guid>
            <description>&lt;img src=&#34;https://bm-sec.de/en/posts/20220504/gruendung.png&#34;  alt=&#34;picture founding&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-html&#34; data-lang=&#34;html&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Note according to the EU AI Act: This content was generated using artificial intelligence.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The company &amp;ldquo;BLACK MONKEY Security GmbH&amp;rdquo; was entered in the commercial register on 04.05.2020.&lt;/p&gt;</description>
            <content type="html"><![CDATA[<img src="/en/posts/20220504/gruendung.png"  alt="picture founding"  class="center"  style="border-radius: 8px;"  />


<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-html" data-lang="html"><span style="display:flex;"><span>Note according to the EU AI Act: This content was generated using artificial intelligence.
</span></span></code></pre></div><p>The company &ldquo;BLACK MONKEY Security GmbH&rdquo; was entered in the commercial register on 04.05.2020.</p>
<p>This is the beginning of an exciting journey in the midst of the global COVID-19 pandemic.</p>]]></content>
        </item>
        
    </channel>
</rss>
