home.social

#iso27001 โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.

  1. Today's pet peeve from reviewing an advisory client's #infosec policies:
    1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
    2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
    #compliance #soc2 #iso27001

  2. ๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด: ๐˜™๐˜ฆ๐˜ฒ๐˜ถ๐˜ช๐˜ณ๐˜ฆ๐˜ฅ ๐˜ฃ๐˜บ ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ญ๐˜ช๐˜ข๐˜ฏ๐˜ค๐˜ฆ, ๐™Ž๐™ฉ๐™ง๐™š๐™ฃ๐™œ๐™ฉ๐™๐™š๐™ฃ๐™š๐™™ ๐™—๐™ฎ ๐™๐™€๐™‡๐™„๐˜ผ๐™‰๐™Š๐™„๐˜ฟ

    From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF โ€” penetration testing is no longer optional. ๐—ฅ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜„๐—ผ๐—ฟ๐—น๐—ฑ๐˜„๐—ถ๐—ฑ๐—ฒ ๐—ฑ๐—ฒ๐—บ๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ ๐˜๐—ต๐—ฎ๐˜ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ฑ๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ๐˜€ ๐—ต๐—ผ๐—น๐—ฑ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป๐˜€๐˜ ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€.

    ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ is the baseline. ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† is the destination. ๐—ช๐—ถ๐˜๐—ต ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐——, ๐˜†๐—ผ๐˜‚ ๐—ด๐—ฒ๐˜ ๐—ฏ๐—ผ๐˜๐—ต.

    relianoid.com/blog/compliance-

  3. We do retros, but nothing changes. "Sound familiar? ๐Ÿ›‘

    #ISO9001 PDCA framework fixes broken feedback loops-turning useless retros into powerful engines for continuous improvement.

    How actionable are your sprint retros? โšก

    #ODIT #ISMS #ISO27001 #Privacy #GDPR #DORA #ISO9001

  4. Scapegoating after an outage only forces devs to hide mistakes. ๐Ÿคซ

    #ISO9001 shifts focus from human error to process failure-turning costly bugs into automated, permanent protections.

    How do you run your post-mortems? ๐Ÿ› ๏ธ

    #ODIT #ISMS #ISO27001 #Privacy #GDPR #DORA

  5. Speed without structure is just chaos. ๐ŸŒช๏ธ

    ISO 9001 turns messy CI/CD pipelines into high-velocity release engines-codifying quality gates and ownership so you scale safely.

    Who signs off on your code before it goes live? โšก

    #ODIT #ISMS #ISO27001 #Privacy #GDPR #DORA #ISO9001

  6. Manual DSAR fire drills pull devs off real work and waste high-cost engineering hours. Automated privacy ops turn manual SQL panics into 1-click compliance.

    How much dev time are you losing to manual DSARs? โšก

    #ODIT #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA

  7. ** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **

    Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
    โ†’ XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!

    hissenit.com/en/blog/it-securi

    #ciso #ceo #awareness #training #nis2 #dora #iso27001

  8. ๐—ข๐—ป๐—ฒ ๐˜ƒ๐—ฒ๐—ป๐—ฑ๐—ผ๐—ฟ ๐—น๐—ฒ๐—ฎ๐—ธ ๐—ฐ๐—ฎ๐—ป ๐—ฟ๐˜‚๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฏ๐—ฟ๐—ฎ๐—ป๐—ฑ. ๐Ÿ“‰

    ISO 27701 locks down third-party risk, proving your entire supply chain is bulletproof. Is third-party risk stalling your pipeline? ๐Ÿ›ก๏ธ

    #ODIT #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA

  9. ๐—ฌ๐—ผ๐˜‚ ๐—ฐ๐—ฎ๐—ปโ€™๐˜ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐—ฑ๐—ฎ๐˜๐—ฎ ๐˜†๐—ผ๐˜‚ ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐—ธ๐—ป๐—ผ๐˜„ ๐—ฒ๐˜…๐—ถ๐˜€๐˜๐˜€. ๐Ÿ—บ๏ธ

    A slick privacy policy on your website won't survive a serious vendor risk assessment. The moment an enterprise prospect asks where customer PII actually lives on your backend, any hesitation destroys buyer trust and stalls the pipeline.

    ISO 27701 bridges the gap between written policy and bulletproof operational proof.

    #ODIT #Governance #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA