Skip to content

Repository files navigation

Security & Open Source Expert | Cloud Security Specialist | Information Security Professional

WebsiteLinkedInGitHubOpenHubISMS-PUBLIC

🎤 Talks & Resources by James Pether Sörling

This repository contains resources and talks by James Pether Sörling, focusing on secure development practices, application security testing, and compliance automation. Below you'll find resources from presentations, security testing tools, and examples for implementing secure practices in your projects.

📋 Contents


🔒 Hack23 AB

Swedish innovation hub specializing in creating immersive and precise game experiences alongside expert cybersecurity consulting and solutions.

🔐 Commitment to Transparency and Security

At Hack23 AB, we believe that true security comes through transparency and demonstrable practices. Our Information Security Management System (ISMS) is publicly available, showcasing our commitment to security excellence and organizational transparency.

📋 Public ISMS Repository

Complete Information Security Management System documentation

ISMS Public Repository

🔒 Information Security Policy

Enterprise-grade security framework and governance

Information Security Policy

🏆 Security Through Transparency

Our approach to cybersecurity consulting is built on a foundation of transparent practices:

  • 🔍 Open Documentation: Complete ISMS framework available for review
  • 📋 Policy Transparency: Detailed security policies and procedures publicly accessible
  • 🎯 Demonstrable Expertise: Our own security implementation serves as a live demonstration
  • 🔄 Continuous Improvement: Public documentation enables community feedback and enhancement

"Our commitment to transparency extends to our security practices - demonstrating that true security comes from robust processes, continuous improvement, and a culture where security considerations are integrated into every business decision."

— James Pether Sörling, CEO/Founder


🍎 Discordian Cybersecurity Insights

Explore information security, ISMS policies, and cybersecurity best practices through the unique Discordian lens inspired by the Illuminatus! trilogy. "Think for yourself, question authority."

📖 Security Blog: 30+ Posts

Everything You Know About Security Is a Lie — Nation-state capabilities, approved crypto paradox, and Chapel Perilous initiation. Complete ISMS coverage with radical transparency.

Discordian Security Blog

Featured Content:

  • 🎭 Discordian Manifesto - Everything You Know About Security Is a Lie
  • 📚 Complete ISMS Coverage - All 30 posts link directly to ISMS-PUBLIC repository
  • 🍎 Illuminatus! Style - FNORD detection, Chapel Perilous references, 23 FNORD 5 signatures

All hail Eris! All hail Discordia! 🍎


🗳️ Riksdagsmonitor

Riksdagsmonitor
Website Status

Swedish Parliament Intelligence Platform monitoring political activity in Sweden's Riksdag with systematic transparency through real-time analysis and 50+ years of historical data (1971-2024).

OpenSSF ScorecardQuality ChecksLicense

OpenSSF ScorecardQuality ChecksDependency ReviewLicenseISMSAsk DeepWiki

🇪🇺 EU Parliament Monitor

EU Parliament Monitor
Release

European Parliament Intelligence Platform — an automated multi-language news platform that monitors EU Parliament activities with 14-language support, covering plenary sessions, committee reports, propositions, and breaking news.

OpenSSF ScorecardSLSA 3License

OpenSSF ScorecardSLSA 3News GenerationTest and ReportLicenseISMSAsk DeepWiki

🔌 European Parliament MCP Server

European Parliament MCP Server
npm version

Model Context Protocol Server for European Parliament Open Data — providing AI assistants with structured access to MEPs, plenary sessions, committees, legislative documents, and parliamentary questions through a secure, type-safe TypeScript implementation.

OpenSSF ScorecardSLSA 3License

OpenSSF ScorecardSLSA 3FOSSA StatusBuild StatusLicenseISMSAsk DeepWiki

🔍 Citizen Intelligence Agency

CIA Logo
Release

Political transparency platform monitoring Swedish political activity with data-driven insights, analytics, dashboard visualizations, and accountability metrics.

CII Best PracticesSLSA 3Security Rating

CII Best PracticesOpenSSF ScorecardSLSA 3Verify & DeployScorecard supply-chain securityQuality Gate StatusSecurity RatingAsk DeepWiki

🔥 Black Trigram (흑괘)

Black Trigram Logo
Release

Realistic 2D precision combat simulator inspired by traditional Korean martial arts, focusing on precise anatomical targeting, authentic combat techniques, and detailed physics-based interactions.

LicenseWebsite Status

OpenSSF ScorecardCII Best PracticesSLSA 3Scorecard supply-chain securityTest & ReportLines of CodeQuality Gate StatusSecurity RatingMaintainability RatingReliability RatingFOSSA StatusAsk DeepWiki

🔐 CIA Compliance Manager

CIA Compliance Manager Logo
Release

Security assessment platform for the CIA triad (Confidentiality, Integrity, Availability) with business impact analysis and compliance mapping to regulatory frameworks like NIST, ISO, GDPR, HIPAA, and SOC2.

CII Best PracticesSLSA 3OpenSSF Scorecard

FOSSA StatusCII Best PracticesOpenSSF ScorecardSLSA 3Verify & ReleaseScorecard Supply-Chain SecurityLines of CodeQuality Gate StatusSecurity RatingMaintainability RatingReliability RatingAsk DeepWiki

🎮 Game Template

Game Template
Release

Secure game development template with React, TypeScript, Three.js, and Vite - built with security-first principles, comprehensive SBOM generation, and automated security testing aligned with Hack23 AB's ISMS.

LicenseOpenSSF Scorecard

LicenseOpenSSF ScorecardAsk DeepWiki

☁️ Lambda in Private VPC

AWS Lambda
CI/CD

Enterprise-grade multi-region active/active architecture with near-zero recovery time, comprehensive DNS failover, and AWS Resilience Hub policy compliance for mission-critical applications.

OpenSSF ScorecardLicense

OpenSSF ScorecardVerify and DeployScorecard Supply-Chain Security

🧪 Sonar-CloudFormation-Plugin

SonarQube Plugin
Maven Central

SonarQube plugin for analyzing AWS CloudFormation templates with security best practices based on NIST, CWE, and ISO standards.

CII Best PracticesOpenSSF Scorecard

LicenseCII Best PracticesOpenSSF Scorecard

🔐 Referenced ISMS Policies

All security practices and compliance approaches discussed in these presentations are backed by Hack23 AB's publicly available Information Security Management System (ISMS). This demonstrates our commitment to security-through-transparency.

ISMS-PUBLIC Repository

Core Security Policies

Policy AreaDocumentDescription
🔐 Information SecurityInformation Security PolicyFoundation of our security management system, defining security principles and governance structure
🛠️ Secure DevelopmentSecure Development PolicyDevSecOps practices, CI/CD security, SAST/DAST/SCA requirements, and compliance automation
📜 Open Source ComplianceOpen Source PolicyOpen source license compliance, SBOM generation, and vulnerability management
🤝 Third-Party ManagementThird Party ManagementVendor security assessment, supply chain risk management, and procurement security
🔍 Vulnerability ManagementVulnerability Management ProcedureSystematic approach to identifying, assessing, and remediating security vulnerabilities

For a complete mapping of presentation topics to ISMS policies, see ISMS_REFERENCE_GUIDE.md.


🔐 Secure Development Pipeline Talk

James Pether Sörling presented this talk at Javaforum Göteborg, where he discussed how to secure your development pipeline with static application security tests (SAST), dynamic application security tests (DAST), and software composition analysis (SCA) using SonarQube.

The presentation covers:

  • Integrating security into CI/CD pipelines
  • DevSecOps implementation strategies
  • Compliance automation techniques
  • Real-world examples of security testing tools

Podcast & Videos:

Presentation Materials:


📜 License Tools for Java Projects

A comprehensive comparison of license compliance tools for Java projects:

This guide covers tools for license detection, compatibility analysis, and compliance management specifically for Java ecosystems.


🛡️ Security Testing Tools

CloudFormation Security

Container Security

CI/CD Examples


🔥 Black Trigram (흑괘)

Black Trigram Logo
Release

Realistic 2D precision combat simulator inspired by traditional Korean martial arts, focusing on precise anatomical targeting, authentic combat techniques, and detailed physics-based interactions.

LicenseWebsite Status

🌟 Featured Projects

🔐 CIA Compliance Manager

CIA Compliance Manager Logo

Security assessment platform for the CIA triad with compliance mapping to regulatory frameworks

LicenseCII Best PracticesSLSA 3

🔍 Citizen Intelligence Agency

CIA Logo

Political transparency platform monitoring Swedish political activity with data-driven insights

LicenseCII Best PracticesSLSA 3

☁️ Lambda in Private VPC

AWS Lambda

Multi-region active/active site leveraging Resilience Hub policy compliance and runbooks

LicenseOpenSSF Scorecard

🧪 Sonar-CloudFormation-Plugin

SonarQube Plugin

SonarQube plugin for analyzing AWS CloudFormation templates with security best practices

LicenseCII Best Practices

🏛️ Project Architecture & Documentation

ProjectCurrent ArchitectureSecurity ArchitectureFuture Vision
CIA Compliance Manager🏛️ Architecture🔒 Security🔮 Future
Citizen Intelligence Agency🏛️ Architecture🔒 Security🔮 Future
ProjectProcess FlowsState DiagramsMindmaps
CIA Compliance Manager📊 Flowcharts🔄 States🧠 Mindmaps
Citizen Intelligence Agency📊 Flowcharts🔄 States🧠 Mindmaps

👤 About Me

Experienced security professional with over 30 years in information technology, specializing in security architecture, cloud security, and compliance. Currently serving as Application Security Officer at Stena Group IT, with prior roles including Information Security Officer at Polestar and Senior Security Architect at WirelessCar. Strong advocate for transparency in organizations, secure software development practices, and innovative open source solutions.

I develop advanced open source tools focused on:

  • 🔐 CIA Triad (Confidentiality, Integrity, Availability)
  • 📊 Compliance Management
  • 🔍 Political Transparency
  • ☁️ Secure Cloud Architectures

🌟 Featured in Press & Media

🗞️ Computer Sweden

Featured article on innovative use of technology for political transparency

Read Article

📰 Riksdag och Departement

Coverage on Citizen Intelligence Agency's monitoring capabilities

Read Article

📊 National Democratic Institute

Recognized in survey of parliamentary monitoring organizations

View Report

📰 Expressen

Eric Erfors credits Citizen Intelligence Agency for exposing politician voting attendance records

Read Article

🎤 Technical Talks & Presentations

🎙️ Javaforum Göteborg

Presentation on secure architecture patterns

Watch Presentation

🎙️ Shift Left Like A Boss

Security podcast guest appearance discussing DevSecOps

Listen to Podcast

🏅 Professional Certifications

CISSPCISMAWS SecurityAWS Solutions Architect

Professional Experience & Skills

%%{
init: {
'theme': 'base',
'themeVariables': {
'primaryColor': '#a0c8e0',
'primaryTextColor': '#1a1a1a',
'primaryBorderColor': '#86b5d9',
'lineColor': '#86b5d9',
'secondaryColor': '#c8e6c9',
'tertiaryColor': '#ffda9e'
}
}
}%%
mindmap
root((James Pether<br>Sörling))
Information Security
::icon(fa fa-shield)
Risk Assessment & Management
CISSP & CISM Certified
Security Architecture Design
Zero Trust Principles
Defense-in-Depth
Compliance Frameworks
ISO 27001
NIST 800-53 VDA-ISA
CIS Controls
GDPR
Security Operations
Incident Response
Vulnerability Management
Security Monitoring
Cloud Security
::icon(fa fa-cloud)
Multi-Cloud Expertise
AWS Advanced
Microsoft Azure
Enterprise Architecture
High Availability Designs
Multi-Region Deployments
Resilience Engineering
Infrastructure as Code
CloudFormation
Terraform
Secure Cloud Services
AWS Security Hub
AWS GuardDuty
KMS Encryption
AWS WAF
Leadership & Governance
::icon(fa fa-users)
Information Security Officer
Security Architect
Policy Development
IT Governance
Team Leadership
Open Source Program Office
AI Governance & Security
Software Engineering
::icon(fa fa-code)
Secure Development (SSDLC)
Java/Spring Full-Stack
TypeScript/JavaScript/React
Automated Testing
CI/CD Pipelines
Code Quality
SLSA Level 3
SonarQube
Open Source Leadership
::icon(fa fa-github)
Project Creator & Maintainer
Community Contributor
Security Tool Development
Code Review
Loading

Career Highlights

%%{
init: {
'theme': 'base',
'themeVariables': {
'primaryColor': '#d1c4e9',
'primaryTextColor': '#1a1a1a',
'primaryBorderColor': '#9575cd',
'lineColor': '#9575cd',
'secondaryColor': '#bbdefb',
'tertiaryColor': '#c8e6c9'
}
}
}%%
timeline
title Professional Journey
section Enterprise Security
2024 : Application Security Officer, Stena Group IT
: Risk Assessment, Cloud Security, Microsoft Azure, AI Governance
2022 - 2024 : Information Security Officer, Polestar
: ISMS Implementation, Security Compliance, Risk Management, OSPO Lead
2018 - 2022 : Senior Security Architect, WirelessCar
: Security Architecture, AWS Security, Secure Development Practices
section Cloud & Security Engineering
2017 - 2018 : Consultant, Consid AB
: Open Source Development, CI/CD, Docker, AWS
2010 - 2017 : Cloud Architect, Keypasco
: Cloud Security Solutions, Multi-Tier Architecture, AWS Infrastructure
section Software Development
2008 - 2009 : Consultant, Redpill Linpro
: Technical Support, System Administration, Development
2006 - 2007 : System Developer, Sky
: J2EE Projects, Agile Development, Test-Driven Development
2003 - 2005 : J2EE Developer, Glu Mobile
: Mobile Services, Integration
2000 - 2002 : Software Engineer, Volantis Systems
: Multi-Channel Server Product Development
Loading

🛠️ Technology & Skills

Security & Compliance

Security ArchitectureRisk ManagementISO 27001NIST 800-53GDPRCIS ControlsVulnerability ManagementIncident ResponseSSDLCAI Governance

Cloud & Infrastructure

AWSCloudFormationAzureLambdaTerraformDockerLinux

Development & Languages

JavaSpringTypeScriptJavaScriptReactPostgreSQL

DevOps & Tools

SonarQubeGitHub ActionsJenkinsOWASP ZAPcfn-nagSLSA


🏆 Notable Contributions & Appearances

  • Information Security Officer at Polestar, leading security practices and the Open Source Program Office
  • Senior Security Architect at WirelessCar, supporting secure delivery practices and security risk management
  • Open source contributor for cfn-nag, developing integration with SonarQube for CloudFormation security analysis
  • Speaker at Javaforum Göteborg on secure architecture patterns
  • Guest on Shift Left Like A Boss security podcast
  • Featured in Computer Sweden and Riksdag och Departement for political transparency work
  • Mentioned in National Democratic Institute survey on parliamentary monitoring organizations
  • Operated Equal Rites BBS in the 1990s, part of Fidonet (Node 2:203/454)
  • committers.top badge

Project Badges & Status

CIA Compliance Manager

GitHub ReleaseLicenseFOSSA StatusCII Best PracticesOpenSSF ScorecardSLSA 3

Citizen Intelligence Agency

GitHub ReleaseCII Best PracticesOpenSSF ScorecardSLSA 3Quality Gate StatusSecurity Rating


🤝 Connect With Me

LinkedInGitHubBlogTech Talks

🔑 Security Services

Professional cybersecurity consulting services delivered remotely or in-person in Gothenburg. Drawing from over three decades of experience in software development and security architecture, we deliver practical security solutions that integrate seamlessly into your development processes without hindering innovation.


📋 Service Overview

🌐 AvailabilityRemote or in-person (Gothenburg)
💰 PricingContact for pricing
🏢 CompanyHack23 AB (Org.nr 5595347807)
📧 ContactLinkedIn

🎯 Core Service Areas

AreaServicesIdeal for
🏗️ Security Architecture & Strategy Enterprise Security Architecture: Design and implementation of comprehensive security frameworks
Risk Assessment & Management: Systematic identification and mitigation of security risks
Security Strategy Development: Alignment of security initiatives with business objectives
Governance Framework Design: Policy development and security awareness programs
Organizations needing strategic security leadership and architectural guidance
☁️ Cloud Security & DevSecOps Secure Cloud Solutions: AWS security assessment and architecture (Advanced level)
DevSecOps Integration: Security seamlessly integrated into agile development processes
Infrastructure as Code Security: Secure CloudFormation, Terraform implementations
Container & Serverless Security: Modern application security best practices
Development teams transitioning to cloud-native architectures with security focus
🔧 Secure Development & Code Quality Secure SDLC Implementation: Building security into development lifecycles
CI/CD Security Integration: Automated security testing and validation
Code Quality & Security Analysis: Static analysis, vulnerability scanning
Supply Chain Security: SLSA Level 3 compliance, SBOM implementation
Development teams seeking to embed security without slowing innovation

🏆 Specialized Expertise

CategoryServicesValue
📋 Compliance & Regulatory Regulatory Compliance: GDPR, NIS2, ISO 27001 implementation
ISMS Design & Implementation: Information Security Management Systems
AI Governance: Emerging AI risk management frameworks
Audit Preparation: Documentation and evidence preparation
Navigate complex regulatory landscapes with confidence
🌐 Open Source Security Open Source Program Office: OSPO establishment and management
Vulnerability Management: Open source risk assessment and remediation
Security Tool Development: Custom security solutions and automation
Community Engagement: Open source security best practices
Leverage open source securely while contributing to security transparency
🎓 Security Culture & Training Security Awareness Programs: Building organization-wide security culture
Developer Security Training: Secure coding practices and methodologies
Leadership Security Briefings: Executive-level security understanding
Incident Response Training: Preparedness and response capability building
Transform security from barrier to enabler through education and culture

💡 Why Choose Hack23 Security Services?

Three decades of hands-on experience in software development and security architecture means we understand the real challenges development teams face. We don't just point out problems—we provide practical, implementable solutions that enhance security without slowing down innovation.

Our approach: Security should be seamlessly integrated into your existing processes, not bolted on afterward. We help organizations build a culture of security awareness where protection becomes a natural part of how teams work, not an obstacle to overcome.

Passionate about transparency: As advocates for open source security, we believe in sharing knowledge and building community. Our solutions are designed to be understandable, maintainable, and aligned with industry best practices.


Profile Views

Last updated: 2025-06-14 16:23:03

About

How to secure your development pipeline with static application security test (SAST) / Dynamic application security test (DAST), software composition analysis (SCA) using Sonarqube.

Topics

Resources

Security policy

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors