# Pragmatic Security — OSSTMM, ISO 27001 & BSI GrundschutzSecurity as provable control, not box-ticking — OSSTMM-measurable testing, a lean ISO 27001 ISMS, BSI Grundschutz baselines, and defense in depth, implemented pragmatically.

Good security is not a certificate on the wall — it is **control you can prove**. We ground our work in three standards that have stood the test of time — **OSSTMM** (measurable, repeatable testing), **ISO 2700x** (a risk-based management system), and **BSI IT-Grundschutz** (a pragmatic baseline-controls catalogue) — and we *live* **defense in depth**: layered controls so no single failure is fatal. The point is the substance, not the paperwork: default-deny, auditable, threat-modelled, verifiable.

We are **OSSTMM/OPSA-certified** (OSSTMM Professional Security Analyst); for ISO 27001 and BSI Grundschutz we are practitioners who have built ISMS repeatedly and taken organizations through (re-)certification — so we can make *you* audit-ready, whether or not you ever need the plaque.

## The standards we use — and what each gives you, pragmatically

| Standard / approach | What it gives you — pragmatically | Where it shows up |
|---|---|---|
| **OSSTMM (ISECOM)** | Measurable, repeatable security testing — facts over opinion, an actual operational-security metric (the `rav`). Analysis that proves control, not checklists. We are OSSTMM/OPSA-certified (Professional Security Analyst). | Security assessments & audits · audit evidence in the [Security & Observability Platform](/portfolio/sovereign-security-observability-platform/) |
| **ISO 2700x** | A lean, risk-based ISMS and controls catalogue — governance, risk treatment and named accountability without the bureaucracy. We have built ISMS and led (re-)certifications. | [Rent-a-Security-Officer](/portfolio/rent-a-security-officer/) · [Rent-a-Data-Protection-Officer](/portfolio/rent-a-data-protection-officer/) |
| **BSI IT-Grundschutz** | A pragmatic baseline of building blocks (Bausteine) and the BSI 200-x method — ISO-27001-compatible, hardening you can apply layer by layer. | Host / network hardening · [Sovereign Edge Firewall](/portfolio/sovereign-edge-firewall/) |
| **Defense in depth (lived)** | The principle that ties them together — layered, default-deny controls so no single failure is fatal, each layer independently auditable. | [Sovereign Edge Firewall](/portfolio/sovereign-edge-firewall/) · [Abusive HTTP Watch](/portfolio/abusive-http-watch/) · [Sovereign Certificate Authority](/portfolio/sovereign-certificate-authority/) · [Security & Observability Platform](/portfolio/sovereign-security-observability-platform/) |

The questions below are grouped for the **CEO** (what to do), the **CIO** (how), the standards and methodology, and working together.
