| ISMS Documentation | β
Fully public on GitHub (30+ policies, 93 controls) | β Proprietary, not shared with clients |
|---|
| Practitioner Status | β
Current Application Security Officer at Stena Group IT | β οΈ Often years removed from hands-on work |
|---|
| Open Source Contributions | β
Active contributor (CIA Manager, Black Trigram, etc.) | β Rarely contribute to community |
|---|
| Security Approach | β
Security enables innovation | β οΈ Often creates bureaucracy and slowdowns |
|---|
| Evidence of Expertise | β
Public security architectures, threat models, policies | β "Trust us" with no verifiable evidence |
|---|
| Development Understanding | β
Deep DevSecOps, CI/CD, cloud-native expertise | β οΈ Limited understanding of modern development |
|---|
| Compliance Frameworks | β
ISO 27001, GDPR, NIS2, CRA, SLSA, NIST | β Usually 1-2 frameworks |
|---|
| Cloud Security | β
AWS certified (Security + Solutions Architect Pro) | β Varies widely |
|---|
| Transparency | β
Radical transparency as core value | β "Security through obscurity" mindset |
|---|
| Learning Resources | β
Public templates, tools, documentation | β Everything proprietary, no knowledge sharing |
|---|