Category: Governance, Risks & Compliance
-

Not what you do, but HOW
Recently we had a P1, but the biggest issue was how we handled it – not that it…
-

The next shift-left: Compliance
With the increase in IT security regulations, Data Governance laws many companies face the challenge, that they have…
-

127 Requirements are Never Equal
The feeling when (TFW) you are handed 127 requirements and need to establish a way to implement and…
-

CSSLP – A Secure Development Practitioner
Gaining a ISC2 CSSLP certificate in Secure Development and what to do about it. The art is in…
-

Testing Corporate CIS18 Security
Let’s help make the implementations more resilient and functional. As always.
-

The Big Hallucination
[First posted on leading-testing-activities.ghost.io, Apr 2025 ] One of my biggest concerns with LLMs is hallucinations. While you…
-

It’s Time for Business Continuity and Exit Plans
How hard is it for you to pull the plug for your IT services and move elsewhere? It’s…
-

Compliance Coaching for the Delivery Teams
I can understand why delivery teams would seem overwhelmed by the volume and think that it’s a hindrance…
-

Problem-solving from the stakeholders’ point of view.
Understanding the landscape is critical whether you’re facing any new situation. One technique that I consistently use is…
-

Have Smarter Compliance Interactions
What matters is everything around the output – not the procedure/guidance/assessment itself. The way you wire your interactions…
100+ Posts since 2012
8 Most Recent Posts
- More about the testing, less about testers
- You are on your own now kid
- What is next after an experienced quality role?
- So I made up the word: Co-delegate
- Keeping track
- Not what you do, but HOW
- Return of the Darlings, Pets, Cattle and GUID’s
- Testing without a System
Frequently featured on Software Testing Weekly, Software testing notes and the Ministry of Testing newsletter.