<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Self on Fr-ISO</title>
    <link>https://www.evers-senne.de/tags/self/</link>
    <description>Recent content in Self on Fr-ISO</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>blog@evers-senne.de (Friso)</managingEditor>
    <webMaster>blog@evers-senne.de (Friso)</webMaster>
    <lastBuildDate>Wed, 26 Feb 2025 00:00:00 +0000</lastBuildDate>
    
        <atom:link href="https://www.evers-senne.de/tags/self/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>Launch day</title>
      <link>https://www.evers-senne.de/post/00_initial_launch/</link>
      <pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate>
      <author>blog@evers-senne.de (Friso)</author>
      <guid>https://www.evers-senne.de/post/00_initial_launch/</guid>
      
        <description>&lt;h2 id=&#34;tldr&#34;&gt;tl;dr&lt;/h2&gt;
&lt;p&gt;Today, I finally launched my &amp;ldquo;Blog and Website&amp;rdquo; project. Topics will touch &lt;em&gt;cybersecurity&lt;/em&gt;, &lt;em&gt;IT@home&lt;/em&gt;, &lt;em&gt;ski mountaineering&lt;/em&gt;.
Starting with two articles about me, but more content is already prepared.&lt;/p&gt;
&lt;h2 id=&#34;why-these-pages&#34;&gt;Why these pages&lt;/h2&gt;
&lt;p&gt;On this website I plan to publish some articles about things I learned, things I am engaged in and topics of my interest.
I am not using any social media very intensively and I want to control my own content, so I decided to do it as in the beginning of the web: create a personal web page. Other channels might be used to post updates with links.&lt;/p&gt;
&lt;h2 id=&#34;who-is-me&#34;&gt;Who is &lt;em&gt;me&lt;/em&gt;&lt;/h2&gt;
&lt;p&gt;See the required &lt;a href=&#34;https://www.evers-senne.de/about/&#34;&gt;Imprint&lt;/a&gt; for the most relevant details. My interests and connections will become visible with dedicated articles. In addition, my nearly unique name might be identifiable in other channels.&lt;/p&gt;
&lt;h2 id=&#34;english-or-german&#34;&gt;English or German?&lt;/h2&gt;
&lt;p&gt;So while my mother tongue is German, writing in English seems mandatory to me to address a wider audience compared to German only. Today&amp;rsquo;s web browser offer translations on the fly, but writing English text myself is a nice training I do not want to miss.
So, if you need a different language, please use the translation feature of your browser.&lt;/p&gt;
&lt;h2 id=&#34;no-comment-feature&#34;&gt;No comment feature?&lt;/h2&gt;
&lt;p&gt;For now I do not offer a comment feature or discussions directly. Please do not hesitate to contact my by mail &lt;a href=&#34;mailto:blog@evers-senne.de&#34;&gt;blog@evers-senne.de&lt;/a&gt; for any questions, corrections are need of discussion.&lt;/p&gt;
</description>
      
    </item>
    
    <item>
      <title>My sports and activities</title>
      <link>https://www.evers-senne.de/post/sports/activities_overview/</link>
      <pubDate>Sun, 23 Feb 2025 00:00:00 +0000</pubDate>
      <author>blog@evers-senne.de (Friso)</author>
      <guid>https://www.evers-senne.de/post/sports/activities_overview/</guid>
      
        <description>&lt;h2 id=&#34;cannot-live-without&#34;&gt;Cannot live without&lt;/h2&gt;
&lt;p&gt;Over the years I developed a passion for multiple outdoor sports, and I took care to find matching sports for summer and winter. When living in north of Germany, road biking was sufficient: Summer and winter are nearly equally cold/warm, terrain nearly flat.
But when moving to the Black Forrest, a hill region in south of Germany, more opportunities came along and the winters are not so nice for biking. So today it splits as follows.&lt;/p&gt;
&lt;h2 id=&#34;summer&#34;&gt;Summer&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Mountain Biking in the Black Forrest and sometimes in the Alps is very much fun. Long up-hills, fast or technical down-hills, not using shaped trails, the terrain is always challenging enough for me.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Road biking is like flying, at least in comparison to mountain biking. But the climbs can also be long and exausting.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Hiking, if all else fails, in the Black Forrest or in the real mountains. This is the activity which is most compatible with other people.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Sometimes: Climbing, Via Ferrata. Doing this to infrequently, the power and technique always fades away over the weeks and month of other sports.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Every now and then: Running, Trail Running. In summer this only fills the last gaps in my calendar.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;winter&#34;&gt;Winter&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ski Mountaineering, as a tour guide and trainer in DAV, I organize multiple events and trainings per year.&lt;/li&gt;
&lt;li&gt;Running is my replacement for cycling, when it is too cold out side. As long as there is no snow in the trails, I prefer trail running. But more or less flat around the lake is at least acceptable.&lt;/li&gt;
&lt;li&gt;Some times: Downhill skiiing. Riding down pistes only happens once or twice a year. Going off-piste is preferred.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;tracking-not-trecking&#34;&gt;Tracking, not trecking&lt;/h2&gt;
&lt;p&gt;Since 2008 I use Garmin devices to record nearly all sportive movements. This gives a nice history of tracks and statistics, from home region and all trips.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://connect.garmin.com/&#34;&gt;Garmin:&lt;/a&gt; &lt;em&gt;jfevers&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.strava.com/athletes/37666215&#34;&gt;Strava:&lt;/a&gt; &lt;em&gt;Jan-Friso Evers-Senne&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Visualizing tracks my self is a different story, will published later.&lt;/p&gt;
</description>
      
    </item>
    
    <item>
      <title>My way into cyber security</title>
      <link>https://www.evers-senne.de/post/cybersecurity/00_my_way/</link>
      <pubDate>Sun, 23 Feb 2025 00:00:00 +0000</pubDate>
      <author>blog@evers-senne.de (Friso)</author>
      <guid>https://www.evers-senne.de/post/cybersecurity/00_my_way/</guid>
      
        <description>&lt;h2 id=&#34;tldr&#34;&gt;tl;dr&lt;/h2&gt;
&lt;p&gt;After many years in the field of computer vision, I switched focus to cybersecurity, more or less by accident. Inside the same company.&lt;/p&gt;
&lt;h2 id=&#34;from-computer-vision-to-device-security&#34;&gt;From computer vision to device security&lt;/h2&gt;
&lt;p&gt;In 2018 my job role suddenly changed from computer vision and image processing to managing development of data loggers. The scope of the project I joined was to develop a small temperature logger working offline most of the time and sending collected data via BlueTooth on button press. The device was 80 % finished and some one asked me to put &amp;ldquo;some security into it&amp;rdquo;.
One brilliant engineer from a different team already had already proposed a concept with asymmetric encryption, private / public keys per device, certificates and an internal certificate authority, but he could not sell it to the development team or the management, so my role was more like understand both worlds, translate between tech and management and finally approve the concept.
The implementation on the microcontroller was difficult due to restrictions in RAM and storage. But with the right libraries it finally worked out.&lt;/p&gt;
&lt;h2 id=&#34;first-steps-to-standardize&#34;&gt;First steps to standardize&lt;/h2&gt;
&lt;p&gt;In parallel to the development project another internal project was launched to define internal security standards for future products. But due to some interesting changes in management, the involved team fall apart. After a review of the very abstract ideas of the former team, I proposed to integrate &amp;ldquo;security&amp;rdquo; into our existing development process by some simple steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Write some basic security requirements on a level that all developers can easily understand and QA can easily test, e.g. &amp;ldquo;Use TLS 1.2 for all HTTPS connections&amp;rdquo;&lt;/li&gt;
&lt;li&gt;Integrate these requirements into the project template sucht that every new project hast to implement or at least check applicability.&lt;/li&gt;
&lt;li&gt;Add a mandatory &amp;ldquo;IoT security concept&amp;rdquo; to the early development phase which describes how to implement the requirements and which is approved by me.&lt;/li&gt;
&lt;li&gt;Add the step of a security analysis (risk assessment) to the development process to discuss remaining risks and assess them.&lt;/li&gt;
&lt;li&gt;Add the mandatory approval of CDO (and me) to the final product release&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;more-than-devices&#34;&gt;More than devices&amp;hellip;&lt;/h2&gt;
&lt;p&gt;From that time on, everybody asked me for my &amp;ldquo;expertise&amp;rdquo; or even opinion when it comes to &amp;ldquo;security&amp;rdquo;. So for example, when customers sent questionnaires about &amp;ldquo;Security&amp;rdquo;, those were directly forward to me, great. These customers were using our cloud software, and they did a vendor assessment, asking many details about the security of the cloud software itself, but also also about our internal security processes.
Answering these vendor assessments, I learned a lot about what we have in place, and even more about what be should have. From some colleagues I heard complains that we need some &amp;ldquo;governance&amp;rdquo;, they were missing an instance giving clear rules and direction. So we proposed our CDO the idea of an  &amp;ldquo;information security governance team&amp;rdquo;. In February 2023 this ISGT was founded and in April I was appointed as the ISO for the company.
To get up to speed I visited different gatherings and so I learned about NIS2  in July 2023
Ok, now my mission for the next year or more was set: NIS2 compliance.&lt;/p&gt;
</description>
      
    </item>
    
    <item>
      <title>Trainings and Certs</title>
      <link>https://www.evers-senne.de/post/cybersecurity/01_certifications/</link>
      <pubDate>Sat, 01 Jun 2024 00:00:00 +0000</pubDate>
      <author>blog@evers-senne.de (Friso)</author>
      <guid>https://www.evers-senne.de/post/cybersecurity/01_certifications/</guid>
      
        <description>&lt;h2 id=&#34;isms-security-officer&#34;&gt;ISMS Security Officer&lt;/h2&gt;
&lt;p&gt;In June 2024 I finished courses and exams at mITSM in Munich and got the title
&lt;em&gt;ICO ISMS Security Officer according to ISO/IEC 27001:2022&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://www.evers-senne.de/https___public.ico-cert.org_badge_user_e66634ec-c258-4f63-a4ab-13d8b0a88e40_badgeClass_71117bb9-7a1e-4df2-9c0f-b597d1355469_1f15ccf0-4d8d-47e5-89dd-ee515e11cc43.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;
&lt;p&gt;Check the badge by downloading (keep filename&amp;quot;!) and pasting here: &amp;ldquo;&lt;a href=&#34;https://badgecheck.io/%22&#34;&gt;https://badgecheck.io/&#34;&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&#34;https://www.evers-senne.de/e66634ec-c258-4f63-a4ab-13d8b0a88e40_a447fa8c-b4c4-4187-831d-c2748394701f_NMEtXM7t0Dyvi0YSE5-sO.pdf&#34;&gt;Final certificate for Security Officer (PDF)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&#34;https://www.evers-senne.de/e66634ec-c258-4f63-a4ab-13d8b0a88e40_c5ed6dae-f103-4cda-992d-f26af7ce8782_M_lYIaspSb-vTomAP876w.pdf&#34;&gt;Second certificate for course Professional&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&#34;https://www.evers-senne.de/e66634ec-c258-4f63-a4ab-13d8b0a88e40_a17956f2-bba7-4e5e-9a25-d036d81694a0_XzMLN7qCSIJvdQzStAI5y.pdf&#34;&gt;First certificate for course Foundation&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description>
      
    </item>
    
  </channel>
</rss>
