Blog

ISA VDA 6.0.3 – The Data Protection sheet explained

The Data Protection catalog is the shortest of the three in ISA 6.0.3 and the one most often underestimated. Twelve control questions across eight subchapters, all numbered under chapter 9. Compared to the roughly sixty questions in Information Security, it looks like an afterthought. It isn’t. It is the part of the assessment where an […]

Why SSDLC is helping shipping faster and more secure code

Software Delivered the Same Way Every Time Before security enters the picture, SDLC exists to solve a simpler problem: making software delivery repeatable. A team that builds features ad hoc, without a defined sequence of requirements, design, coding, testing, and release, ends up with wildly inconsistent outcomes — some releases solid, others full of regressions, […]

Security User Stories How-To – for product managers and developers

I wrote some time ago about “How to create security user stories” and I received in the meanwhile a lot of good feedback and questions about it. For these reasons, I decided that it is time to write again on the topic, this time with focus on two importat groups in any software developer team: […]

ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance

This is the part 5 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance   Chapter 6 — Supplier Relationships This chapter addresses how the organization manages information security risks arising […]

ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security

This is the part 4 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1). ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security Chapter 5 — IT Security / Cyber Security This is the largest chapter in the Information […]