Open Source Conference Luxembourg

From inventory to compliance: a fully open source ecosystem for cybersecurity

Running information security governance without proprietary software or single-vendor lock-in is not only possible — it is proven in production. This talk shows how five open source tools, most of them European and several built in Luxembourg, fit together into one coherent chain: GLPI (asset inventory), Mercator (information system cartography), MONARC (risk analysis), Deming (ISO 27001 ISMS management), and Vulnerability-Lookup / CPE Guesser (vulnerability intelligence). Each excels in its own domain; together they cover the full cycle of compliance, risk management and asset inventory — with no proprietary lock-in.


The talk follows the flow of data, from the concrete up to governance:

  1. GLPI establishes the factual baseline — which hardware, software, licences and contracts actually exist.
  2. Mercator turns that inventory into a structured map (ecosystem, business, application, logical and physical views) — what depends on what, which flows, which data.
  3. MONARC takes those assets as objects of risk analysis (threats, vulnerabilities, treatment).
  4. Deming runs the ISMS: Statement of Applicability, ISO 27002 controls, action plans, audit evidence — fed by the risk treatment.
  5. Vulnerability-Lookup closes the loop, continuously matching the CPEs of inventoried software against published CVEs.
    The core message: these are not competing silos but an interoperable ecosystem, where each tool consumes and enriches the data of the others.
Didier Barzin

Hi there, I'm Didier, a technology and information security enthusiast. I started my career as an information security Ninja, defending information systems against cyber threats using my Jedi skills. However, I also have another side to me that comes out at night, that of a benevolent hacker. I love using my skills to support the values of open source and firmly believe in them.

I believe that technology can be used to improve people's lives, but this can only be done if we work together and share our knowledge. That's why I'm also a strong advocate of collaboration and openness in the tech industry.

May the source code be with you!