Endpoint Cybersecurity GmbH
- Why SSDLC is helping shipping faster and more secure code
- Security User Stories How-To – for product managers and developers
- ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance
- ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security
- ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management
- ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization
- TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1)
- AI Adoption for companies in the USA
- AI Adoption for companies (based on OECD data)
- SOC 2 Type 2 mapping to Secure SDLC Requirements



Understanding ISO 27001:2022 Annex A.5 – Information Security Policies
/in EducationalWe started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. We start today with A.5. Information Security Policies. Contents Toggle Importance of Information Security Policies Implementing Annex A.5 in Practice Auditing Compliance with Annex A.5 Importance of Information Security Policies Information security policies […]
Annex A of ISO 27001:2022 explained and tips to prepare for an audit
/in EducationalWe wrote in the previous article ISO 27001:2022: chapter by chapter description about ISO 27001:2022 Annex A. Annex A of ISO 27001:2022 is a vital component of the standard, outlining a comprehensive set of controls that organizations can implement to mitigate information security risks effectively. These controls cover a wide range of areas, including physical security, […]
ISO 27001:2022: chapter by chapter description
/in EducationalContents Toggle What’s New in ISO 27001:2022 Chapter 1-3: Scope, Normative References and Terms and Definitions Chapter 4: Context of the Organization Goal Actions Implementation Chapter 5: Leadership Goal Actions Implementation Chapter 6: Planning Goal Actions Implementation Chapter 7: Support Goal Actions Implementation Chapter 8: Operation Goal Actions Implementation Chapter 9: Performance Evaluation Chapter 10: […]
The ISO 27000 family of protocols and their role in cybersecurity
/in EducationalThe ISO 27000 family of protocols represent a series of standards developed by the International Organization for Standardization (ISO) to address various aspects of information security management. These standards provide a framework for organizations to establish, implement, maintain, and continually improve their information security management systems (ISMS). Each standard within the ISO 27000 family serves […]
Building Resilient Web Applications on AWS: A Comprehensive Approach to Security
/in EducationalContents Toggle Securing the Presentation Layer Risk Assessment at the Presentation Layer Security practices Securing the Business Logic Layer Risk Assessment at the Business Logic Layer Securing the Database Level Risk Assessment at the Database Level Continuous Monitoring and Response Conclusion I have been asked by friends and customers what is the best way […]