home.social

#iso27001 โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.

  1. Today's pet peeve from reviewing an advisory client's #infosec policies:
    1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
    2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
    #compliance #soc2 #iso27001

  2. ๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด: ๐˜™๐˜ฆ๐˜ฒ๐˜ถ๐˜ช๐˜ณ๐˜ฆ๐˜ฅ ๐˜ฃ๐˜บ ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ญ๐˜ช๐˜ข๐˜ฏ๐˜ค๐˜ฆ, ๐™Ž๐™ฉ๐™ง๐™š๐™ฃ๐™œ๐™ฉ๐™๐™š๐™ฃ๐™š๐™™ ๐™—๐™ฎ ๐™๐™€๐™‡๐™„๐˜ผ๐™‰๐™Š๐™„๐˜ฟ

    From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF โ€” penetration testing is no longer optional. ๐—ฅ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜„๐—ผ๐—ฟ๐—น๐—ฑ๐˜„๐—ถ๐—ฑ๐—ฒ ๐—ฑ๐—ฒ๐—บ๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ ๐˜๐—ต๐—ฎ๐˜ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ฑ๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ๐˜€ ๐—ต๐—ผ๐—น๐—ฑ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป๐˜€๐˜ ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€.

    ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ is the baseline. ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† is the destination. ๐—ช๐—ถ๐˜๐—ต ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐——, ๐˜†๐—ผ๐˜‚ ๐—ด๐—ฒ๐˜ ๐—ฏ๐—ผ๐˜๐—ต.

    relianoid.com/blog/compliance-

  3. GRC Platforms vs. Managed Compliance: Understanding the Gaps

    TL;DR

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:
    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
    If nobody can answer that today, thatโ€™s the gap youโ€™re actually buying a solution for โ€” not the framework name on the badge.

    Btw, If the 2 a.m. question above didnโ€™t have a clean answer, itโ€™s worth a look at what a fully managed model covers versus whatโ€™s still sitting on your teamโ€™s plate. Check out the Espresso Labs platform

    If youโ€™ve bought a GRC (governance, risk management, and compliance) tool in the last five years, youโ€™ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someoneโ€™s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didnโ€™t fix anything.

    That gap โ€” between visibility and operationalization โ€” is worth thinking about carefully, because itโ€™s where a lot of compliance budget quietly goes to die.

    What GRC platforms like Vanta and Drata actually solve

    Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet โ€” the one where โ€œevidenceโ€ meant a screenshot pasted into a folder six weeks before the audit. What they do well:

    • Pull control status from the tools you already run via read-only integrations
    • Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
    • Automate evidence collection so audit season isnโ€™t a fire drill
    • Alert you when something drifts out of policy

    For a company with a mature security function โ€” people who own EDR, MDM, SSO, backup, and vulnerability management day to day โ€” this is exactly the layer you want. It turns โ€œprove youโ€™re compliantโ€ from an annual archaeology project into a live, queryable system.

    The quiet assumption baked into that model

    Hereโ€™s the thing these platforms assume, and itโ€™s almost never stated out loud in the sales process: you already have the underlying security program.

    The dashboard reports on controls; it doesnโ€™t implement them, enforce them, or fix them when they break.

    When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone โ€” on your team, or a vendor youโ€™ve separately hired โ€” has to:

    1. Triage it
    2. Actually go fix it (device by device, user by user)
    3. Confirm the fix took
    4. Make sure it doesnโ€™t regress next sprint

    For a company with a five-person security team and a mature IT function, thatโ€™s Tuesday. For the median SMB or mid-market company โ€” the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist โ€” that queue just grows. You end up with excellent visibility into a program that isnโ€™t actually being run.

    This is also why โ€œweโ€™re SOC 2 compliantโ€ and โ€œweโ€™re actually secureโ€ are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.

    Naming the other model: managed enforcement

    Thereโ€™s a second category worth knowing about, and itโ€™s growing for a reason: fully managed IT/security/compliance services that donโ€™t just monitor your stack, they are the stack โ€” implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.

    The pitch, generalized across this category, usually includes:

    • Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
    • Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
    • 24/7 monitoring of the actual environment, not just what connected tools self-report
    • Automated or human-assisted remediation when something drifts
    • Incident response bundled in, rather than โ€œbring your own IR retainerโ€
    • One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together

    For a lean team, that consolidation is genuinely attractive. Itโ€™s also worth being honest about what youโ€™re trading away.

    What a CISO should actually diligence before choosing either path

    This is the part vendor comparison pages conveniently skip, so hereโ€™s the checklist Iโ€™d actually run:

    If youโ€™re leaning toward a GRC dashboard (Vanta/Drata/similar):

    • Do you have a named owner for every control category who will actually close findings, not just watch them?
      Whatโ€™s your median time-to-remediate on a flagged finding today? If you donโ€™t know, thatโ€™s the answer.
      Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?

    If youโ€™re leaning toward a managed compliance/enforcement service:

    • Who owns the risk when something goes wrong โ€” contractually, not just in the sales deck? Compliance liability doesnโ€™t fully transfer just because implementation did.
    • Can they show you audit history and named references from companies in your size band and framework, not just logos?
    • Whatโ€™s the actual SLA on remediation and incident response, in writing, with penalties โ€” not โ€œ24/7 monitoringโ€ as a marketing phrase?
    • How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems โ€” understand the blast radius if that relationship ends badly or that vendor itself has an incident.
    • Is there a subcontractor chain? Ask whoโ€™s actually touching your environment at 2 a.m., not just whose logo is on the contract.
    • Does their AI-driven remediation have a human escalation path you control, or does โ€œautomatedโ€ mean โ€œopaqueโ€?

    Neither model is inherently safer.
    A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.

    The mistake is buying the dashboard and assuming itโ€™s the program, or buying the managed service and assuming youโ€™ve fully offloaded accountability โ€” you havenโ€™t. Your board and your regulator still hold you responsible.

    The one-line version

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:

    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?

    If nobody can answer that today, thatโ€™s the gap youโ€™re actually buying a solution for โ€” not the framework name on the badge.

    Curious where you actually stand?

    If the 2 a.m. question above didnโ€™t have a clean answer, itโ€™s worth a look at what a fully managed model covers versus whatโ€™s still sitting on your teamโ€™s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.

    Rate this:

    #AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2
  4. When you get ISO 27001 certified, you commit to an ongoing process: systematically identifying risks, implementing measures, and having them audited repeatedly โ€“ not just once, but on an ongoing basis. ๐Ÿ“‹ In an age where โ€œdata securityโ€ is often just a marketing promise, we back ours up with an independent audit. ๐Ÿ‘‰ Learn more about us and our certifications: nine.ch/en/infrastructure/#dat #iso27001 #iso9001 #informationsecurity #qualitymanagement #nine

  5. ๐Ÿ” Milestone for information security at Hallo Welt! GmbH๐Ÿ”

    Hallo Welt! GmbH has successfully obtained ISO/IEC 27001 certification. This means that an independent testing agency has confirmed our information security management system (ISMS) and our structured approach to handling sensitive data.๐Ÿฅณ

    Find out more here: bluespice.com/iso-certificatio

  6. ๐Ÿ” Third-Party Risk Management at RELIANOID

    At RELIANOID, security and resilience extend beyond our own platform. We apply strict Third-Party Risk Management (TPRM) practices to ensure that every vendor, partner, or supplier meets our high standards for security, compliance, and reliability.

    More details: relianoid.com/security-complia

  7. ๐Ÿ† BSI C5-Testat fรผr mailbox bestรคtigt vollstรคndige Erfรผllung der BSI-Kriterien fรผr Cloud-Sicherheit!

    mailbox ist ab sofort mit dem C5-Typ1-Testat des Bundesamts fรผr Sicherheit in der Informationstechnik ausgezeichnet. Das BSI C5-Testat ergรคnzt die ISO/IEC 27001-Zertifizierung von mailbox.

    Erfahren Sie mehr รผber unsere Cloud-Sicherheitsstandards: mailbox.org/de/news/bsi-c5-tes

    #BSI #C5Testat #ISO27001 #CloudSicherheit #Informationssicherheit #Datensicherheit #mailbox

  8. ๐Ÿ“ฃ If you're managing domains and DNS while pursuing compliance certifications, Infrastructure as Code isn't optional, it's essential ๐Ÿ‘Š.
    The DNSimple Terraform provider makes this possible with full domain lifecycle management, giving you the tools to manage #domains and #DNS with the same rigor you apply to other critical infrastructure.
    โŒ No more manual tweaks risking errors or failed reviews.

    ๐Ÿ‘‰ blog.dnsimple.com/2025/12/doma

    #SOC2 #ISO27001 #Compliance #AuditReadiness, #infrastructureAsCode