ISM Logs
BSI 100-4 covers emergency management (business continuity), providing a methodology for establishing and maintaining an organization-wide emergency management system.
Key characteristics:
Methodology for business continuity management (BCM)
Creates a standalone management syste...
Q A "Value at Risk" analysis is meant to answer who/why, what/how, and where/when about a cyberattack....
Who and why = threat types and their motivations; what and how = the type and technical sophistication of the attack; where and when = the organization's vulnerability measured against a cyber-resilience maturity level.
"Who and why" addresses target attractiveness and threat mot...
Q What is a "Threat Matrix" of adversary versus intent, and what does each axis represent?
A Threat Matrix maps types of adversary (rows) against types of target (columns) and fills each cell with the intent — the kind of harm that actor would pursue against that target.
* Threat Matrix — adversary types (rows) × target groups (columns); each cell names the intent, co...
Q What is the purpose of comparing a "current state" against a "desired state" for each security measu...
The gap between where a control is today (current) and where it needs to be (desired) is exactly the work the improvement roadmap must fund — it makes the investment case concrete and prioritizable.
For each measure (segmentation, access management, XDR monitoring, incident respo...
Q What is the relationship between ISO 27001 certification and BSI IT-Grundschutz?
An ISO 27001 certificate based on IT-Grundschutz includes both an ISMS audit and a verification of concrete IT security measures — making it more rigorous than a standard ISO 27001 certification.
ISO 27001 on IT-Grundschutz:
Covers both the ISMS (management system) and the concr...
Q Who is the Ponemon Institute, and why is its "Cost of a Data Breach" research widely cited in securi...
The Ponemon Institute (founded 2002) is an independent research organization focused on information and privacy management; its annual breach-cost study gives security teams credible, comparable money figures.
The cited edition examined 600 organizations across 16 countries and 1...
Q In an adversary-versus-intent Threat Matrix, what kinds of intent would a state-sponsored actor typi...
State-sponsored actors lean toward espionage, sabotage, and information manipulation; criminal actors lean toward disruption, system manipulation, and information theft (for money).
The split reflects motive. Nation-state actors pursue strategic goals — stealing secrets (espionag...
Q The final step of the exercise is "draft the improvement roadmap." What makes a good security roadma...
A good roadmap is risk-based and prioritized — it sequences the control gaps (step 6) by the impact and likelihood of the threats they address, so the most important protections come first.
It is last because every earlier step feeds it: the industry and high-value asset (steps 1...
Q Why is management support essential for information security, and what does Swiss law say about mana...
Without management support, there are no resources, no authority, and no priority for information security. Under Swiss law (OR Art. 754), management cannot fully delegate this responsibility.
Without management support you get:
No resources (time and money)
No authority (power...
Q According to recent Ponemon "Cost of a Data Breach" figures, roughly what is the global average brea...
The global average total cost of a data breach is about USD 4.4 million (around EUR 3.9 million); in healthcare it is far higher, about USD 7.42 million.
The global average actually fell for the first time in five years, partly because faster investigations cut detection and esca...