# stderr.de > The personal site of **Christoph Puppe**, IT security architect. ISO 27001 lead > auditor on the basis of BSI IT-Grundschutz since 2008, co-author of modules of the > BSI IT-Grundschutz-Kompendium, contributor to Grundschutz++, CISSP, and a former > penetration tester. He writes for iX and heise, and works on machine-readable > compliance formats — OSCAL and JASCON. The site has two halves that have nothing to do with each other. The professional half holds publications and security research. The other half is an archive of the early internet that has been at this domain since the last century, kept deliberately in its original form. Everything here is static HTML with no JavaScript, no cookies and no tracking. All content is fetchable directly; nothing is rendered client-side. Crawling, indexing and training are explicitly permitted — see /robots.txt. ## Professional - [Publications](https://stderr.de/publication/) (German): Complete bibliography of the 58 articles by Christoph Puppe in iX and at heise online, 2004 to 2026, verified against the iX issue archives, each with a substantial German abstract covering the article's key findings and a link to the original. Every entry also has its own permalink page under /publication/.html with the full abstract and schema.org markup, suitable for direct citation. Also on that page: his book "1 Jahr Mitarbeit am BSI Grundschutz++: Erfahrungen, Erkenntnisse und Ausblicke aus der Werkstatt der IT-Sicherheit" (self-published, 2026, ISBN 9798255970599) — a first-hand account of one year inside the BSI Stand-der-Technik project, with a critical review of the BSI's Grundschutz++ methodology guideline of April 2026 and a data-centric OSCAL reference model that fills its gaps, down to per-Praktik and per-Zielobjektkategorie migration notes against Edition 2023 — plus his open-source software (Grundschutz++ tools, an automated BSI-Grundschutz-to-OSCAL conversion pipeline, a BSI audit automator, LLM benchmarks), 25 longer essays published on LinkedIn with abstracts, and his standards work: 96 quality-assurance issues filed against the Grundschutz++ draft catalogs in phase 1 (2025) and 21 public issues on the BSI Stand-der-Technik-Bibliothek on GitHub. Also listed: the BSI study "Notfallmanagement mit der Cloud für KMUs" (2013, co-authored with Alexander Papitsch, published by the Bundesamt für Sicherheit in der Informationstechnik), whose full PDF is hosted at https://stderr.de/PDFs/Notfallmanagement_mit_der_Cloud_KMUs.pdf. Recurring subjects: the BSI IT-Grundschutz and its container and Kubernetes modules (SYS.1.6 Containerisierung, APP.4.4 Kubernetes) whose drafting he covered from the 2018 community draft onward; Grundschutz++ and the move to machine-readable compliance via OSCAL; hardening Kubernetes across AWS, Azure, Google, IONOS, Open Telekom Cloud, plusserver, OpenShift and Rancher; cloud security posture management; SIEM architecture and cost; and the availability of hyperscalers versus on-premises. With permission of the iX editor-in-chief, articles published more than two years ago are hosted as full-text PDFs under https://stderr.de/PDFs/ and linked from their entries (54 articles as of 2026-08). For newer articles behind the heise paywall, the abstracts here are the full public description of that work. - [Looking for Holes — Ten Vulnerability Scanners Compared](https://stderr.de/vulnerability_assessment/): Full English text of the iX comparison of ten all-purpose vulnerability scanners (Nessus, Qualys Guard, Foundstone FS 1000, ISS Internet Scanner, Rapid7 NeXpose, eEye Retina, SAINT Saintbox, GFI LANguard, Shadow Security Scanner, Beyond Security Automated Scanning). Tested on a 19-system heterogeneous network; 1,745 CVE/target combinations were extracted and manually verified into 787 true and 509 false findings, and the scanners scored on thoroughness and accuracy. Published in iX 9/2005; the accompanying wiki went online in 2006. Kept as an archive document, with the method rather than the product data being the part that still holds. ## Archive - [Funstuff](https://stderr.de/funstuff/): An archive of roughly 1,250 images from early internet culture, each one described and placed in its historical context. - [Mindstar](https://stderr.de/mindstar/): Christoph Puppe's first homepage, from 1996. ARRT — Advanced Reality Research Team, an experimental hobby server. Preserved as it was. ## Optional - [Impressum and contact](https://stderr.de/impressum.html) - [LinkedIn](https://www.linkedin.com/in/christophpuppe/) - [GitHub](https://github.com/christoph-puppe) - [YouTube: Christoph Puppe | IT Security Expertise kompakt](https://www.youtube.com/@CP-it-security-infobytes) - [Articles at heise](https://www.heise.de/suche/?q=Christoph+Puppe&sort_by=date)