#iso27000

Jonathan Kamens 86 47jik@federate.social
2025-05-09

ISO 27000 nit #3. I had to stare at this for several minutes to try to figure out what "enhancing societal values" was doing in this list. IMO the meaning of all the other list items it clear, but that one's clear as mud. I _think_ what they're trying to get at is improving the security culture within the organization being managed, but honestly, that's just a guess, I'm not even certain that's what they mean.
#infosec #compliance #ISO #ISO27000 #standards #isms

The following fundamental principles also contribute to the successful
implementation of an ISMS:
a) awareness of the need for information security;
b) assignment of responsibility for information security;
c) incorporating management commitment and the interests of stakeholders;
d) enhancing societal values;
e) risk assessments determining appropriate controls to reach acceptable levels of risk;
f) security incorporated as an essential element of information networks and systems;
g) active prevention and detection of information security incidents;
h) ensuring a comprehensive approach to information security management;
i) continual reassessment of information security and making of modifications as appropriate.
Jonathan Kamens 86 47jik@federate.social
2025-05-09

ISO 27000 nit #2: The definition of "risk" provided here, "effect of uncertainty on objectives," is dumb, obscure, unhelpful, bureaucratic gobbledygook. It in no way resembles the dictionary definition of risk, which much more closely approximates what I think of when I use the word risk or see it used in an information security concept. I am challenged to understand why they chose this nonsense definition and what they hope to achieve by it.
#infosec #compliance #ISO #ISO27000 #standards #isms

Jonathan Kamens 86 47jik@federate.social
2025-05-09

I am reviewing ISO 27000, as one does for shits and giggles, and I am curious about the motivation behind making "interested party" the preferred term while "stakeholder" is allowed but not preferred.
In the contexts in which I see stakeholder used, I believe it is a more accurate term than "interested party." Preferring the latter term IMO obfuscates meaning rather than clarifying it.
#infosec #compliance #ISO #ISO27000 #standards #isms

Roger Bellorogerbelloo
2024-08-09
Nikka Systems Sverigenikkasystemsse
2023-05-22

Nätfiskare kan kombinera två attack­metoder för att skapa riktigt vilse­ledande länkar. Firefox är den enda webbläsaren som åtminstone skyddar delvis. Vi förklarar problemet och berättar vad som bör göras åt det.

nikkasystems.com/2023/05/22/we

2022-12-01

I #crochet lapghans while watching #compliance webinars about how much #ISO27000 2022 is going to be a nightmare for me!

2022-07-26

Half-a-dozen learning points from a '27001 certification announcement - This morning I bumped into a marketing/promotional piece announcing PageProof’s ce... blog.noticebored.com/2022/07/h #confidentiality #availability #bestpractice #compliance #governance #assurance #integrity #iso27000 #strategy #infosec #metrics #impact

2022-07-24

Risk management trumps checklist security - While arguably better than nothing at all, an unstructured approach to the manage... blog.noticebored.com/2022/07/r #bestpractice #compliance #governance #iso27000 #infosec #risk

2022-07-21

ISO management systems assurance - In the context of the ISO management systems standards, the internal audit process... blog.noticebored.com/2022/07/i #assurance #iso27000

2022-06-30

What are "information assets"? - Control 5.9 in ISO/IEC 27002:2022 recommends an inventory of information assets th... blog.noticebored.com/2022/06/w #bestpractice #compliance #iso27000 #secaware #control #infosec #tools

2022-06-27

The business context for information risk and security - Although the organisational/business context is clearly relevant and important to... blog.noticebored.com/2022/06/t #relationships #bestpractice #compliance #governance #iso27000 #outsider #secaware #strategy #culture #infosec #insider #tools #risk

2022-06-24

The sadly neglected Risk Treatment Plan -  For some curious reason, the Statement of Applicability steals the limelight in t... blog.noticebored.com/2022/06/t #accountability #bestpractice #compliance #governance #innovation #assurance #iso27000 #secaware #strategy #control #infosec #audit #tools #risk

2022-06-21

Infosec principles (Hinson tips) - Thinking about the principles underpinning information risk and security, here's a... blog.noticebored.com/2022/06/i #bestpractice #governance #innovation #resilience #awareness #incidents #iso27000 #strategy #control #infosec #tools #risk

2022-06-20

WANTED: a set of infosec principles we can all agree on - The SecAware corporate information security policy template incorporates a set of ... blog.noticebored.com/2022/06/w #bestpractice #compliance #governance #iso27000 #strategy #infosec #policy #tools #risk

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst