A-R-C

Insights & Articles

Analysis of information security, ISMS, security governance, EU/DACH market requirements and SaaS trust.

Product Security Governance · 2026-08-01

SBOM Governance: Why a Component List Is Not Enough

Effective SBOM practice connects standardised product data to quality rules, vulnerability triage, supplier governance and documented decisions.

SBOMProduct SecurityCyber Resilience ActSupplier GovernanceVulnerability Management

NIS2 & Security Governance · 2026-07-27

NIS2 Reporting: From Implementation Status to Risk Decision

How to turn NIS2 implementation status into a defensible risk decision by connecting business impact, effectiveness, accountability and executive action.

NIS2BSIGManagement ReportingSecurity Governance

ISO 27001 & CISO · 2026-07-11

Are ISO 27001 and a CISO Required by Law?

When ISO 27001 or a CISO function becomes relevant through law, contract or governance, with sources on the BSIG, NIS2, GDPR and German company law.

ISMSGovernanceLaw