This is how we proceed
We work in three verifiable steps and coordinate the result, responsibility and next decision point in advance.
- Model threats, protection needs, and supply chain risks for the specific application context
- Integrate appropriate controls into architecture, development platform, and delivery pipeline
- Check detection and response with realistic scenarios and prioritize improvements in a comprehensible way
Practice & Orientation
Translating safety requirements into engineering
Discuss risks in the system design
Data flows, trust boundaries and external dependencies form the basis for a threat model. This results in concrete requirements for identities, interfaces and the processing of confidential data.
Incorporate testing into the development process
Code checking, dependency analysis and traceable approvals help to identify findings at an early stage. A result must be assigned to a team and lead to an editable improvement process.
Delivering the operation
Security-relevant protocols, emergency access, secret management and update procedures are part of the handover. The documentation should explain how a system is maintained and restored in a controlled manner in the event of problems.