#iso27001 โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.
-
Today's pet peeve from reviewing an advisory client's #infosec policies:
1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
#compliance #soc2 #iso27001 -
๐ฃ๐ฒ๐ป๐๐ฒ๐๐๐ถ๐ป๐ด: ๐๐ฆ๐ฒ๐ถ๐ช๐ณ๐ฆ๐ฅ ๐ฃ๐บ ๐๐ฐ๐ฎ๐ฑ๐ญ๐ช๐ข๐ฏ๐ค๐ฆ, ๐๐ฉ๐ง๐๐ฃ๐๐ฉ๐๐๐ฃ๐๐ ๐๐ฎ ๐๐๐๐๐ผ๐๐๐๐ฟ
From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF โ penetration testing is no longer optional. ๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป๐ ๐๐ผ๐ฟ๐น๐ฑ๐๐ถ๐ฑ๐ฒ ๐ฑ๐ฒ๐บ๐ฎ๐ป๐ฑ ๐ผ๐ฟ๐ด๐ฎ๐ป๐ถ๐๐ฎ๐๐ถ๐ผ๐ป๐ ๐ฝ๐ฟ๐ผ๐๐ฒ ๐๐ต๐ฎ๐ ๐๐ต๐ฒ๐ถ๐ฟ ๐ฑ๐ฒ๐ณ๐ฒ๐ป๐๐ฒ๐ ๐ต๐ผ๐น๐ฑ ๐ฎ๐ด๐ฎ๐ถ๐ป๐๐ ๐ฟ๐ฒ๐ฎ๐น-๐๐ผ๐ฟ๐น๐ฑ ๐๐ต๐ฟ๐ฒ๐ฎ๐๐.
๐๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ is the baseline. ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ is the destination. ๐ช๐ถ๐๐ต ๐ฅ๐๐๐๐๐ก๐ข๐๐, ๐๐ผ๐ ๐ด๐ฒ๐ ๐ฏ๐ผ๐๐ต.
#Pentesting #CyberSecurity #Compliance #ISO27001 #PCI #SOC2 #HIPAA #GLBA #GDPR #SWIFT #InfoSec
-
We do retros, but nothing changes. "Sound familiar? ๐
#ISO9001 PDCA framework fixes broken feedback loops-turning useless retros into powerful engines for continuous improvement.
How actionable are your sprint retros? โก
-
Scapegoating after an outage only forces devs to hide mistakes. ๐คซ
#ISO9001 shifts focus from human error to process failure-turning costly bugs into automated, permanent protections.
How do you run your post-mortems? ๐ ๏ธ
-
If you have ADHD, then #ISO27001 **will** kill you.
-
Speed without structure is just chaos. ๐ช๏ธ
ISO 9001 turns messy CI/CD pipelines into high-velocity release engines-codifying quality gates and ownership so you scale safely.
Who signs off on your code before it goes live? โก
-
** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **
Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
โ XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
-
๐ข๐ป๐ฒ ๐๐ฒ๐ป๐ฑ๐ผ๐ฟ ๐น๐ฒ๐ฎ๐ธ ๐ฐ๐ฎ๐ป ๐ฟ๐๐ถ๐ป ๐๐ผ๐๐ฟ ๐ฏ๐ฟ๐ฎ๐ป๐ฑ. ๐
ISO 27701 locks down third-party risk, proving your entire supply chain is bulletproof. Is third-party risk stalling your pipeline? ๐ก๏ธ
#ODIT #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA
-
๐ฌ๐ผ๐ ๐ฐ๐ฎ๐ปโ๐ ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐ ๐ฑ๐ฎ๐๐ฎ ๐๐ผ๐ ๐ฑ๐ผ๐ปโ๐ ๐ฒ๐๐ฒ๐ป ๐ธ๐ป๐ผ๐ ๐ฒ๐ ๐ถ๐๐๐. ๐บ๏ธ
A slick privacy policy on your website won't survive a serious vendor risk assessment. The moment an enterprise prospect asks where customer PII actually lives on your backend, any hesitation destroys buyer trust and stalls the pipeline.
ISO 27701 bridges the gap between written policy and bulletproof operational proof.
#ODIT #Governance #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA
-
๐ Milestone for information security at Hallo Welt! GmbH๐
Hallo Welt! GmbH has successfully obtained ISO/IEC 27001 certification. This means that an independent testing agency has confirmed our information security management system (ISMS) and our structured approach to handling sensitive data.๐ฅณ
Find out more here: https://bluespice.com/iso-certification/
-
๐ Third-Party Risk Management at RELIANOID
At RELIANOID, security and resilience extend beyond our own platform. We apply strict Third-Party Risk Management (TPRM) practices to ensure that every vendor, partner, or supplier meets our high standards for security, compliance, and reliability.
More details: https://www.relianoid.com/security-compliances/relianoid-third-party-risk-management-policy/
#RELIANOID #ThirdPartyRiskManagement #CyberSecurity #Compliance #DORA #NIS2 #GDPR #ISO27001 #OperationalResilience #SupplyChainSecurity
-
๐ฅ Die Highlights unseres Know-how to go zum Thema "ISMS Automatisierung & Risikomanagement" sind jetzt online!
Unsere Expertinnen und Experten haben spannende Einblicke zu aktuellen Themen rund um Informationssicherheit geteilt โ jetzt sind die Vortrรคge als Video verfรผgbar! Die drei kompakten Vortrรคge zeigen
๐ก Agile ISMS-Einfรผhrung mit Scrum: ๏ปฟhttps://youtu.be/4ngy_FHcAwQ
๐ Git-basiertes ISMS ohne Word & Excel: ๏ปฟhttps://youtu.be/YVIN48DRv_g
๐ Risikomanagement mit Projektmanagement-Tools: ๏ปฟhttps://youtu.be/f680GkVdSHk
#ISMS #ISO27001 #Risikomanagement #AgileSecurity #Informationssicherheit #Cybersecurity
-
๐ฆ๐๐ฉ๐ ๐ง๐๐ ๐๐๐ง๐: ๐๐ผ๐๐๐ฒ๐ป๐ณ๐ฟ๐ฒ๐ถ๐ฒ๐ ๐๐ป๐ผ๐-๐ต๐ผ๐ ๐๐ผ ๐ด๐ผ ๐ฎ๐บ ๐ฎ๐ฒ.๐ญ๐ญ. ๐ถ๐ป ๐๐ฒ๐ฟ๐น๐ถ๐ป
๐ HiSolutions Know-how to go: ISMS Automatisierung & Risikomanagement
Informationssicherheit muss heute flexibel, transparent und praxisnah gestaltet werden. In drei kompakten Vortrรคgen zeigen unsere Experten auf, wie sich Normanforderungen mit modernen Arbeitsweisen verbinden lassen, Aufgaben im #ISMS automatisiert werden kรถnnen und damit weniger Belastung bei den Verantwortlichen (CISO/ISB) liegt โ effizient, skalierbar und zukunftsfรคhig.๐ก Agile ISMS-Einfรผhrung mit Scrum
๐ Git-basiertes ISMS ohne Word & Excel
๐ Risikomanagement mit Projektmanagement-ToolsDie Teilnahme an unserem Wissensfrรผhstรผck ist kostenfrei.
Wann: 26.11.2025 | Wo: Berlin
Weiter Infos und Anmeldung: โถ๏ธ https://www.hisolutions.com/knowhow#ISMS #ISO27001 #Risikomanagement #AgileSecurity #Informationssicherheit #Cybersecurity
-
ISO 27701: Risikobeurteilung und Risikobehandlung
Die Begriffe Risikobeurteilung und Risikobehandlung sind zentrale Themen fรผr Unternehmen, die Datenschutz und Informationssicherheit effektiv umsetzen wollen. In diesem Beitrag wird der Risikobegriff nach ISO 27701 und der DSGVO erlรคutert, Unterschiede herausgearbeitet und praxisnahe Umsetzungstipps(...)
https://www.dr-datenschutz.de/iso-27701-risikobeurteilung-und-risikobehandlung/ -
Chainlink Hits Compliance Milestone as LINK Active Addresses Reach 10,000 - TLDR:
Chainlink earned ISO 27001 and SOC 2 compliance, validating its security and opera... - https://blockonomi.com/chainlink-hits-compliance-milestone-as-link-active-addresses-reach-10000/ #proofofreserve #stablecoins #blockchain #pricefeeds #chainlink #linkprice #smartdata #iso27001 #fintech #navlink #oracles #crypto #defi #ccip #soc2