CSA STAR Level 1 — 보안 자체 평가
Gexiro Global Enterprises Ltd. 는 ChimeraScope에 대한 CSA STAR Level 1 Security Self-Assessment를 공개했습니다. 이 등록은 명시된 평가 범위를 문서화합니다. Level 1은 자체 평가이며 독립적인 보안 감사나 제3자 인증이 아닙니다.
CSA STAR 등록 보기
운영자 교육 이력
Bartosz Joachimiak은 다음 Linux Foundation 과정을 이수했습니다.
Cybersecurity Essentials (LFC108) — 2026-06-19
Developing Secure Software (LFD121) — 2026-09-04
Securing Your Software Supply Chain with Sigstore (LFS182) — 2026-09-04
Automating Supply Chain Security: SBOMs and Signatures (LFEL1007) — 2026-09-05
Secure AI/ML-Driven Software Development (LFEL1012) — 2026-09-05
Conversational AI: Ensuring Compliance and Mitigating Risks (LFS120) — 2026-09-05
Understanding the EU Cyber Resilience Act (CRA) (LFEL1001) — 2026-09-05
Qualys - Certificate of Completion
CyberSecurity Asset Management - 2026년 8월 27일 수료.
Global Cyber Alliance - 수료한 7개 과정
Understanding Cyber Risk for Small Business - 2026년 6월 16일
Creating Strong Passwords & Two-Factor Authentication - 2026년 6월 16일
Protect Against Email Spoofs & Phishing - 2026년 6월 16일
Protect Against Phishing & Malware - 2026년 6월 16일
Protecting Your Business Data with Backups - 2026년 6월 16일
Software Updates & Business Security - 2026년 6월 16일
How to Inventory Your Devices, Apps & Accounts - 2026년 6월 16일
Hack Smarter Labs - 수료한 실습 Challenge Lab 9개
Challenge Lab: Casino (Medium) - 수료일 2026년 8월 25일
Challenge Lab: Exception (Medium) - 수료일 2026년 8월 25일
Challenge Lab: GitOops (Medium) - 수료일 2026년 8월 25일
Challenge Lab: HealthSmarter (Medium) - 수료일 2026년 8월 25일
Challenge Lab: Second (Medium) - 수료일 2026년 8월 25일
Challenge Lab: SysAdmins (Medium) - 수료일 2026년 8월 25일
Challenge Lab: Kiosk (Medium) - 수료일 2026년 8월 26일
Challenge Lab: Race Conditions (Medium) - 수료일 2026년 8월 31일
Challenge Lab: GateCrasher (Easy) - 수료일 2026년 9월 5일
CISA / Idaho National Laboratory — ICS 과정 15개 수료(4.30 CEU)
ICS Cybersecurity Practices (100W) — 2026-08-31
Differences in Deployments of ICS (210W-01) — 2026-08-31
Influence of IT Components on ICS (210W-02) — 2026-08-31
Common ICS Components (210W-03) — 2026-08-31
Cybersecurity Within IT and ICS Domains (210W-04) — 2026-09-01
ICS Cybersecurity Risk (210W-05) — 2026-09-01
ICS Cybersecurity Threats (210W-06) — 2026-09-01
ICS Cybersecurity Vulnerabilities (210W-07) — 2026-09-01
ICS Cybersecurity Consequences (210W-08) — 2026-09-02
Attack Methodologies in IT & ICS (210W-09) — 2026-09-02
Mapping IT Defense-In-Depth Security Solutions to ICS - Part I (210W-10) — 2026-09-04
Mapping IT Defense-In-Depth Security Solutions to ICS - Part II (210W-11) — 2026-09-04
ICS Cybersecurity (300) — 2026-09-04
ICS Cybersecurity Evaluation (401) — 2026-09-05
ICS Cybersecurity Landscape for Managers (FRE2115) — 2026-09-05
CyberDefenders — 실습 랩 2개 완료
CyberDefenders: GetPDF (Blue Team) — 2026-09-06
CyberDefenders: l337 S4uc3 (Medium, Endpoint Forensics) — 2026-09-06
이는 Bartosz Joachimiak 개인의 과정 이수 기록이며 ChimeraScope, Gexiro 또는 해당 서비스의 인증이 아닙니다.
평가 범위
평가는 기본적으로 수동적 방식으로 수행됩니다. 능동적 상호작용은 명시적으로 합의되고 승인된 범위에서만 수행합니다. 결과는 전달 전에 사람의 검증을 거칩니다.
내부 보안 자체 평가
내부 검토에서는 OWASP ASVS v5.0 Level 1 및 CIS Controls v8 Implementation Group 1의 일부 요구사항을 참조합니다. 이는 자체 평가이며 독립 인증이나 제3자 감사가 아닙니다.
책임 있는 공개
보안 보고는 공개된 Vulnerability Disclosure Policy 및 security.txt 채널을 통해 제출할 수 있으며, 공개 PGP 키를 사용한 암호화 연락도 가능합니다.
증거와 평가 범위 논의하기 업무에 적용되는 증거, 범위 및 제공 모델을 검토하려면 Gexiro에 문의하십시오.
문의하기