home.social

#iso27001 โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.

  1. Today's pet peeve from reviewing an advisory client's #infosec policies:
    1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
    2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
    #compliance #soc2 #iso27001

  2. ๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด: ๐˜™๐˜ฆ๐˜ฒ๐˜ถ๐˜ช๐˜ณ๐˜ฆ๐˜ฅ ๐˜ฃ๐˜บ ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ญ๐˜ช๐˜ข๐˜ฏ๐˜ค๐˜ฆ, ๐™Ž๐™ฉ๐™ง๐™š๐™ฃ๐™œ๐™ฉ๐™๐™š๐™ฃ๐™š๐™™ ๐™—๐™ฎ ๐™๐™€๐™‡๐™„๐˜ผ๐™‰๐™Š๐™„๐˜ฟ

    From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF โ€” penetration testing is no longer optional. ๐—ฅ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜„๐—ผ๐—ฟ๐—น๐—ฑ๐˜„๐—ถ๐—ฑ๐—ฒ ๐—ฑ๐—ฒ๐—บ๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ ๐˜๐—ต๐—ฎ๐˜ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ฑ๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ๐˜€ ๐—ต๐—ผ๐—น๐—ฑ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป๐˜€๐˜ ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€.

    ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ is the baseline. ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† is the destination. ๐—ช๐—ถ๐˜๐—ต ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐——, ๐˜†๐—ผ๐˜‚ ๐—ด๐—ฒ๐˜ ๐—ฏ๐—ผ๐˜๐—ต.

    relianoid.com/blog/compliance-