home.social

#iso27001 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.

  1. Today's pet peeve from reviewing an advisory client's #infosec policies:
    1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
    2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
    #compliance #soc2 #iso27001

  2. 𝗣𝗲𝗻𝘁𝗲𝘀𝘁𝗶𝗻𝗴: 𝘙𝘦𝘲𝘶𝘪𝘳𝘦𝘥 𝘣𝘺 𝘊𝘰𝘮𝘱𝘭𝘪𝘢𝘯𝘤𝘦, 𝙎𝙩𝙧𝙚𝙣𝙜𝙩𝙝𝙚𝙣𝙚𝙙 𝙗𝙮 𝙍𝙀𝙇𝙄𝘼𝙉𝙊𝙄𝘿

    From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF — penetration testing is no longer optional. 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻𝘀 𝘄𝗼𝗿𝗹𝗱𝘄𝗶𝗱𝗲 𝗱𝗲𝗺𝗮𝗻𝗱 𝗼𝗿𝗴𝗮𝗻𝗶𝘇𝗮𝘁𝗶𝗼𝗻𝘀 𝗽𝗿𝗼𝘃𝗲 𝘁𝗵𝗮𝘁 𝘁𝗵𝗲𝗶𝗿 𝗱𝗲𝗳𝗲𝗻𝘀𝗲𝘀 𝗵𝗼𝗹𝗱 𝗮𝗴𝗮𝗶𝗻𝘀𝘁 𝗿𝗲𝗮𝗹-𝘄𝗼𝗿𝗹𝗱 𝘁𝗵𝗿𝗲𝗮𝘁𝘀.

    𝗖𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝗰𝗲 is the baseline. 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 is the destination. 𝗪𝗶𝘁𝗵 𝗥𝗘𝗟𝗜𝗔𝗡𝗢𝗜𝗗, 𝘆𝗼𝘂 𝗴𝗲𝘁 𝗯𝗼𝘁𝗵.

    relianoid.com/blog/compliance-

  3. ** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **

    Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
    → XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!

    hissenit.com/en/blog/it-securi

    #ciso #ceo #awareness #training #nis2 #dora #iso27001

  4. GRC Platforms vs. Managed Compliance: Understanding the Gaps

    TL;DR

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:
    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
    If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.

    Btw, If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform

    If you’ve bought a GRC (governance, risk management, and compliance) tool in the last five years, you’ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someone’s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didn’t fix anything.

    That gap — between visibility and operationalization — is worth thinking about carefully, because it’s where a lot of compliance budget quietly goes to die.

    What GRC platforms like Vanta and Drata actually solve

    Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet — the one where “evidence” meant a screenshot pasted into a folder six weeks before the audit. What they do well:

    • Pull control status from the tools you already run via read-only integrations
    • Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
    • Automate evidence collection so audit season isn’t a fire drill
    • Alert you when something drifts out of policy

    For a company with a mature security function — people who own EDR, MDM, SSO, backup, and vulnerability management day to day — this is exactly the layer you want. It turns “prove you’re compliant” from an annual archaeology project into a live, queryable system.

    The quiet assumption baked into that model

    Here’s the thing these platforms assume, and it’s almost never stated out loud in the sales process: you already have the underlying security program.

    The dashboard reports on controls; it doesn’t implement them, enforce them, or fix them when they break.

    When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone — on your team, or a vendor you’ve separately hired — has to:

    1. Triage it
    2. Actually go fix it (device by device, user by user)
    3. Confirm the fix took
    4. Make sure it doesn’t regress next sprint

    For a company with a five-person security team and a mature IT function, that’s Tuesday. For the median SMB or mid-market company — the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist — that queue just grows. You end up with excellent visibility into a program that isn’t actually being run.

    This is also why “we’re SOC 2 compliant” and “we’re actually secure” are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.

    Naming the other model: managed enforcement

    There’s a second category worth knowing about, and it’s growing for a reason: fully managed IT/security/compliance services that don’t just monitor your stack, they are the stack — implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.

    The pitch, generalized across this category, usually includes:

    • Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
    • Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
    • 24/7 monitoring of the actual environment, not just what connected tools self-report
    • Automated or human-assisted remediation when something drifts
    • Incident response bundled in, rather than “bring your own IR retainer”
    • One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together

    For a lean team, that consolidation is genuinely attractive. It’s also worth being honest about what you’re trading away.

    What a CISO should actually diligence before choosing either path

    This is the part vendor comparison pages conveniently skip, so here’s the checklist I’d actually run:

    If you’re leaning toward a GRC dashboard (Vanta/Drata/similar):

    • Do you have a named owner for every control category who will actually close findings, not just watch them?
      What’s your median time-to-remediate on a flagged finding today? If you don’t know, that’s the answer.
      Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?

    If you’re leaning toward a managed compliance/enforcement service:

    • Who owns the risk when something goes wrong — contractually, not just in the sales deck? Compliance liability doesn’t fully transfer just because implementation did.
    • Can they show you audit history and named references from companies in your size band and framework, not just logos?
    • What’s the actual SLA on remediation and incident response, in writing, with penalties — not “24/7 monitoring” as a marketing phrase?
    • How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems — understand the blast radius if that relationship ends badly or that vendor itself has an incident.
    • Is there a subcontractor chain? Ask who’s actually touching your environment at 2 a.m., not just whose logo is on the contract.
    • Does their AI-driven remediation have a human escalation path you control, or does “automated” mean “opaque”?

    Neither model is inherently safer.
    A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.

    The mistake is buying the dashboard and assuming it’s the program, or buying the managed service and assuming you’ve fully offloaded accountability — you haven’t. Your board and your regulator still hold you responsible.

    The one-line version

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:

    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?

    If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.

    Curious where you actually stand?

    If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.

    Rate this:

    #AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2
  5. Cuando hablamos de un roadmap de ciberseguridad, casi siempre la conversación empieza igual:

    Zero Trust.
    ISO 27001.
    NIST.
    EDR.
    SIEM.

    Pero... ¿y si estuviéramos empezando por el lugar equivocado?

    Hace más de cincuenta años, James P. Anderson propuso algo sorprendentemente actual: antes de pensar en controles o tecnologías, primero hay que entender qué estamos protegiendo, de quién y bajo qué supuestos.

    El problema no siempre es elegir un framework incorrecto. Muchas veces el problema es intentar aplicar cualquier framework sin haber comprendido primero el entorno.

    Quizás por eso seguimos resolviendo problemas modernos con herramientas cada vez mejores... mientras repetimos errores que ya habían sido identificados décadas atrás.

    En este artículo
    medium.com/@jack.of.all.trades

    analizo por qué un roadmap de ciberseguridad debería comenzar mucho antes de hablar de Zero Trust, ISO 27001 o NIST.

    #CyberSecurity #InfoSec #ZeroTrust #ISO27001 #NIST #Architecture #RiskManagement #JamesAnderson

  6. 🔐 Milestone for information security at Hallo Welt! GmbH🔐

    Hallo Welt! GmbH has successfully obtained ISO/IEC 27001 certification. This means that an independent testing agency has confirmed our information security management system (ISMS) and our structured approach to handling sensitive data.🥳

    Find out more here: bluespice.com/iso-certificatio

  7. 🔐 Third-Party Risk Management at RELIANOID

    At RELIANOID, security and resilience extend beyond our own platform. We apply strict Third-Party Risk Management (TPRM) practices to ensure that every vendor, partner, or supplier meets our high standards for security, compliance, and reliability.

    More details: relianoid.com/security-complia

  8. 📣 If you're managing domains and DNS while pursuing compliance certifications, Infrastructure as Code isn't optional, it's essential 👊.
    The DNSimple Terraform provider makes this possible with full domain lifecycle management, giving you the tools to manage #domains and #DNS with the same rigor you apply to other critical infrastructure.
    ❌ No more manual tweaks risking errors or failed reviews.

    👉 blog.dnsimple.com/2025/12/doma

    #SOC2 #ISO27001 #Compliance #AuditReadiness, #infrastructureAsCode

  9. Currently going home from a 2 day internal #auditor #training from #DNV I followed with my entire team, with focus on #ISO27001. Despite the fact we've been doing them since forever, there still where some interesting points for all of us that we can use. There is always room for improvement!

    Lunches where good too 🥪😏.

    #today #audit #auditing #ISMS #datasecurity

  10. Currently going home from a 2 day internal #auditor #training from #DNV I followed with my entire team, with focus on #ISO27001. Despite the fact we've been doing them since forever, there still where some interesting points for all of us that we can use. There is always room for improvement!

    Lunches where good too 🥪😏.

    #today #audit #auditing #ISMS #datasecurity