ISO 27000 nit #3. I had to stare at this for several minutes to try to figure out what "enhancing societal values" was doing in this list. IMO the meaning of all the other list items it clear, but that one's clear as mud. I _think_ what they're trying to get at is improving the security culture within the organization being managed, but honestly, that's just a guess, I'm not even certain that's what they mean.
#infosec #compliance #ISO #ISO27000 #standards #isms
ISO 27000 nit #2: The definition of "risk" provided here, "effect of uncertainty on objectives," is dumb, obscure, unhelpful, bureaucratic gobbledygook. It in no way resembles the dictionary definition of risk, which much more closely approximates what I think of when I use the word risk or see it used in an information security concept. I am challenged to understand why they chose this nonsense definition and what they hope to achieve by it.
#infosec #compliance #ISO #ISO27000 #standards #isms
I am reviewing ISO 27000, as one does for shits and giggles, and I am curious about the motivation behind making "interested party" the preferred term while "stakeholder" is allowed but not preferred.
In the contexts in which I see stakeholder used, I believe it is a more accurate term than "interested party." Preferring the latter term IMO obfuscates meaning rather than clarifying it.
#infosec #compliance #ISO #ISO27000 #standards #isms
LinkedIn: Log In or Sign Up

1 billion members | Manage your professional identity. Build and engage with your professional network. Access knowledge, insights and opportunities.

LinkedIn
LinkedIn: Log In or Sign Up

1 billion members | Manage your professional identity. Build and engage with your professional network. Access knowledge, insights and opportunities.

LinkedIn

Nätfiskare kan kombinera två attack­metoder för att skapa riktigt vilse­ledande länkar. Firefox är den enda webbläsaren som åtminstone skyddar delvis. Vi förklarar problemet och berättar vad som bör göras åt det.

https://nikkasystems.com/2023/05/22/webblasare-tillater-uppenbar-natfiskemetod/

#blisäker #nätfiske #phishing #chrome #firefox #edge #safari #cisv8 #iso27000

Webbläsare tillåter uppenbar nätfiske­metod – Nikka Systems

Nätfiskare kan kombinera två attack­metoder för att skapa riktigt vilse­ledande länkar. Firefox är den enda webbläsaren som åtminstone skyddar delvis.

Nikka Systems
I #crochet lapghans while watching #compliance webinars about how much #ISO27000 2022 is going to be a nightmare for me!
Half-a-dozen learning points from a '27001 certification announcement - This morning I bumped into a marketing/promotional piece announcing PageProof’s ce... http://blog.noticebored.com/2022/07/half-dozen-learning-points-from-27001.html #confidentiality #availability #bestpractice #compliance #governance #assurance #integrity #iso27000 #strategy #infosec #metrics #impact
Half-a-dozen learning points from a '27001 certification announcement

6 lessons from Pageproof's ISOIEC 27001 certification

Risk management trumps checklist security - While arguably better than nothing at all, an unstructured approach to the manage... http://blog.noticebored.com/2022/07/risk-management-trumps-checklist.html #bestpractice #compliance #governance #iso27000 #infosec #risk
Risk management trumps checklist security

Explains the advantages of ISO27k's risk-driven approach over checklist security