Audit-Strategien für eine erfolgreiche Zertifizierung
In jedem Unternehmen steigen Spannung und Aufregung, wenn der Termin des Zertifizierungsaudits näher rückt. Allerdings gibt es einige Schritte, die diese Zeit entspannter gestalten können und dabei die Sicherheit erhöhen, dass man das Zertifizierungsaudit erfolgreich besteht.
Readiness-Audit als Vo(...)
https://www.dr-datenschutz.de/audit-strategien-fuer-eine-erfolgreiche-zertifizierung/
#Informationssicherheitssysteme und #ISO27000er-Familie
1:25 Std.
#Informationssicherheitsmanagementsystem (#ISMS) - #PDCA-Zyklus
ISO/ #IEC27000er-Normenreihe
- Begriffs-, Anforderungs- und #LeitfadenNormen
- #Phasenmodell für ISMS-#Implementierung u. Betrieb aus #27001:2013 ableiten
- Neuerungen in ISO/IEC 27001:2022 und #ISO27002:2022
#informationssicherheitsmanagement #iso27000 #Informationssicherheit
Mit meinem Link ist #LinkedInLearning Kurs kostenlos.
https://www.linkedin.com/posts/activity-7163581589052932096-X5AD?utm_source=share&utm_medium=member_android
The more I read ISO 27001 and ISO 27002 the more I ponder whether they really work in the way I would like them to.
Yes, they provide frameworks for managing IT risk but, at least in my decades of experience, the problems are:
* pragmatism: still far too much "security theatre" going on, we are still at the TSA stage of IT security,
* management buy-in: as long as the ISO 27001 certificate is obtained in some way or another the management is happy. The emphasis is "in some way" and, in the immortal Italian tradition, "fatta la legge trovato l'inganno"¹.
While I do appreciate that the deception of the law applies all over the place the security theatre part still irks me. The industry should by now be mature, the good ol' [Karger74]² is, well, old and yet it seems someone re-writes it on a semi-daily basis. Some of the stuff written in it should be blindingly obvious by now but no, not in ITsec.
I don't actually have a solution so I guess this has just turned into an "old man shouts at The Cloud" (this meme has been updated for 2023, unlike ITsec).
Go back to installing a root-privileged anti-virus, sorry "smart security agent", on your machine.
Love,
#ISO27001 #ISO27002 #ISOmyarse
__
¹ "law made, deception found" (although it sounds so much better in Italian)
² P. Karger and R. Schell, "Multics Security Evaluation: Vulnerability Analysis" https://csrc.nist.rip/publications/history/karg74.pdf (PDF)
Has ISO27002 improved enough? In today’s blog, Lucia gives her thoughts on the changes to the controls and the new additions.
ISO27002 changes are coming.
Our latest blog post breaks down the key factors and timelines for your business.