Skip to main content

Search...

Security, Regulation & Compliance

Security testing and regulatory, standards-based, and compliance requirements for software quality.

Articles

Podcast Episodes

Using open source securely

Anyone who installs open source components needs a bill of materials - because 80 to 95 percent of modern software is in them. What licenses, security vulnerabilities and the Cyber Resilience Act have to do with it.

Fuzzy Testing

Fuzzing sounds like chaos, but it's a method: How random input systematically reveals security vulnerabilities and why targeted test data is more useful than pure chance.

Automated security checks

Pen tests at the end of a project always find the same things: headers, misconfigurations, standard gaps. Integrating security into the pipeline reduces this to 4 to 5 really critical findings.

Secure by Design

Security is often the last item on the agenda - and that is precisely the problem. What defense in depth, threat modeling and secure defaults really mean.

Security analyses

Why security in the development team hardly gets through despite a high level of awareness, and which approach really works in practice.

Court expert

Those who accept software usually only test functions. Whether up to 12,000 undiscovered bugs are normal and what "state of the art" really means in legal terms.

Automotive testing

Automotive testing: a windshield wiper is already considered a safety-critical system. What this means for test methods, standards and everyday life as a tester.