home.social

#iso27001 โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.

  1. Today's pet peeve from reviewing an advisory client's #infosec policies:
    1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
    2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
    #compliance #soc2 #iso27001

  2. ๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด: ๐˜™๐˜ฆ๐˜ฒ๐˜ถ๐˜ช๐˜ณ๐˜ฆ๐˜ฅ ๐˜ฃ๐˜บ ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ญ๐˜ช๐˜ข๐˜ฏ๐˜ค๐˜ฆ, ๐™Ž๐™ฉ๐™ง๐™š๐™ฃ๐™œ๐™ฉ๐™๐™š๐™ฃ๐™š๐™™ ๐™—๐™ฎ ๐™๐™€๐™‡๐™„๐˜ผ๐™‰๐™Š๐™„๐˜ฟ

    From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF โ€” penetration testing is no longer optional. ๐—ฅ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜„๐—ผ๐—ฟ๐—น๐—ฑ๐˜„๐—ถ๐—ฑ๐—ฒ ๐—ฑ๐—ฒ๐—บ๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ ๐˜๐—ต๐—ฎ๐˜ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ฑ๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ๐˜€ ๐—ต๐—ผ๐—น๐—ฑ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป๐˜€๐˜ ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€.

    ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ is the baseline. ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† is the destination. ๐—ช๐—ถ๐˜๐—ต ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐——, ๐˜†๐—ผ๐˜‚ ๐—ด๐—ฒ๐˜ ๐—ฏ๐—ผ๐˜๐—ต.

    relianoid.com/blog/compliance-

  3. We do retros, but nothing changes. "Sound familiar? ๐Ÿ›‘

    #ISO9001 PDCA framework fixes broken feedback loops-turning useless retros into powerful engines for continuous improvement.

    How actionable are your sprint retros? โšก

    #ODIT #ISMS #ISO27001 #Privacy #GDPR #DORA #ISO9001

  4. Scapegoating after an outage only forces devs to hide mistakes. ๐Ÿคซ

    #ISO9001 shifts focus from human error to process failure-turning costly bugs into automated, permanent protections.

    How do you run your post-mortems? ๐Ÿ› ๏ธ

    #ODIT #ISMS #ISO27001 #Privacy #GDPR #DORA

  5. Speed without structure is just chaos. ๐ŸŒช๏ธ

    ISO 9001 turns messy CI/CD pipelines into high-velocity release engines-codifying quality gates and ownership so you scale safely.

    Who signs off on your code before it goes live? โšก

    #ODIT #ISMS #ISO27001 #Privacy #GDPR #DORA #ISO9001

  6. Manual DSAR fire drills pull devs off real work and waste high-cost engineering hours. Automated privacy ops turn manual SQL panics into 1-click compliance.

    How much dev time are you losing to manual DSARs? โšก

    #ODIT #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA

  7. ** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **

    Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
    โ†’ XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!

    hissenit.com/en/blog/it-securi

    #ciso #ceo #awareness #training #nis2 #dora #iso27001

  8. ๐—ข๐—ป๐—ฒ ๐˜ƒ๐—ฒ๐—ป๐—ฑ๐—ผ๐—ฟ ๐—น๐—ฒ๐—ฎ๐—ธ ๐—ฐ๐—ฎ๐—ป ๐—ฟ๐˜‚๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฏ๐—ฟ๐—ฎ๐—ป๐—ฑ. ๐Ÿ“‰

    ISO 27701 locks down third-party risk, proving your entire supply chain is bulletproof. Is third-party risk stalling your pipeline? ๐Ÿ›ก๏ธ

    #ODIT #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA

  9. ๐—ฌ๐—ผ๐˜‚ ๐—ฐ๐—ฎ๐—ปโ€™๐˜ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐—ฑ๐—ฎ๐˜๐—ฎ ๐˜†๐—ผ๐˜‚ ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐—ธ๐—ป๐—ผ๐˜„ ๐—ฒ๐˜…๐—ถ๐˜€๐˜๐˜€. ๐Ÿ—บ๏ธ

    A slick privacy policy on your website won't survive a serious vendor risk assessment. The moment an enterprise prospect asks where customer PII actually lives on your backend, any hesitation destroys buyer trust and stalls the pipeline.

    ISO 27701 bridges the gap between written policy and bulletproof operational proof.

    #ODIT #Governance #CyberSecurity #InfoSec #ISMS #ISO27001 #Privacy #GDPR #DORA

  10. ๐Ÿ” Milestone for information security at Hallo Welt! GmbH๐Ÿ”

    Hallo Welt! GmbH has successfully obtained ISO/IEC 27001 certification. This means that an independent testing agency has confirmed our information security management system (ISMS) and our structured approach to handling sensitive data.๐Ÿฅณ

    Find out more here: bluespice.com/iso-certificatio

  11. ๐Ÿ” Third-Party Risk Management at RELIANOID

    At RELIANOID, security and resilience extend beyond our own platform. We apply strict Third-Party Risk Management (TPRM) practices to ensure that every vendor, partner, or supplier meets our high standards for security, compliance, and reliability.

    More details: relianoid.com/security-complia

  12. ๐ŸŽฅ Die Highlights unseres Know-how to go zum Thema "ISMS Automatisierung & Risikomanagement" sind jetzt online!

    Unsere Expertinnen und Experten haben spannende Einblicke zu aktuellen Themen rund um Informationssicherheit geteilt โ€“ jetzt sind die Vortrรคge als Video verfรผgbar! Die drei kompakten Vortrรคge zeigen

    ๐Ÿ’ก Agile ISMS-Einfรผhrung mit Scrum: ๏ปฟyoutu.be/4ngy_FHcAwQ

    ๐Ÿ“ Git-basiertes ISMS ohne Word & Excel: ๏ปฟyoutu.be/YVIN48DRv_g

    ๐Ÿ“Š Risikomanagement mit Projektmanagement-Tools: ๏ปฟyoutu.be/f680GkVdSHk

    #ISMS #ISO27001 #Risikomanagement #AgileSecurity #Informationssicherheit #Cybersecurity

  13. ๐—ฆ๐—”๐—ฉ๐—˜ ๐—ง๐—›๐—˜ ๐——๐—”๐—ง๐—˜: ๐—ž๐—ผ๐˜€๐˜๐—ฒ๐—ป๐—ณ๐—ฟ๐—ฒ๐—ถ๐—ฒ๐˜€ ๐—ž๐—ป๐—ผ๐˜„-๐—ต๐—ผ๐˜„ ๐˜๐—ผ ๐—ด๐—ผ ๐—ฎ๐—บ ๐Ÿฎ๐Ÿฒ.๐Ÿญ๐Ÿญ. ๐—ถ๐—ป ๐—•๐—ฒ๐—ฟ๐—น๐—ถ๐—ป
    ๐Ÿ“…HiSolutions Know-how to go: ISMS Automatisierung & Risikomanagement
    Informationssicherheit muss heute flexibel, transparent und praxisnah gestaltet werden. In drei kompakten Vortrรคgen zeigen unsere Experten auf, wie sich Normanforderungen mit modernen Arbeitsweisen verbinden lassen, Aufgaben im #ISMS automatisiert werden kรถnnen und damit weniger Belastung bei den Verantwortlichen (CISO/ISB) liegt โ€“ effizient, skalierbar und zukunftsfรคhig.

    ๐Ÿ’ก Agile ISMS-Einfรผhrung mit Scrum
    ๐Ÿ“ Git-basiertes ISMS ohne Word & Excel
    ๐Ÿ“Š Risikomanagement mit Projektmanagement-Tools

    Die Teilnahme an unserem Wissensfrรผhstรผck ist kostenfrei.

    Wann: 26.11.2025 | Wo: Berlin
    Weiter Infos und Anmeldung: โ–ถ๏ธ hisolutions.com/knowhow

    #ISMS #ISO27001 #Risikomanagement #AgileSecurity #Informationssicherheit #Cybersecurity

  14. ISO 27701: Risikobeurteilung und Risikobehandlung

    Die Begriffe Risikobeurteilung und Risikobehandlung sind zentrale Themen fรผr Unternehmen, die Datenschutz und Informationssicherheit effektiv umsetzen wollen. In diesem Beitrag wird der Risikobegriff nach ISO 27701 und der DSGVO erlรคutert, Unterschiede herausgearbeitet und praxisnahe Umsetzungstipps(...)
    dr-datenschutz.de/iso-27701-ri

    #ISO27001 #ISO27701 #Risikomanagement