#iso27001 โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iso27001, aggregated by home.social.
-
Today's pet peeve from reviewing an advisory client's #infosec policies:
1) compliance mills who give their clients a business continuity _policy_ mislabeled as a business continuity _plan_ so they can claim for compliance purposes that a plan exists when it really doesn't; and
2) auditors who let audit subjects get away with calling a policy a plan, rather than dinging them for it and making them create a real plan.
#compliance #soc2 #iso27001 -
๐ฃ๐ฒ๐ป๐๐ฒ๐๐๐ถ๐ป๐ด: ๐๐ฆ๐ฒ๐ถ๐ช๐ณ๐ฆ๐ฅ ๐ฃ๐บ ๐๐ฐ๐ฎ๐ฑ๐ญ๐ช๐ข๐ฏ๐ค๐ฆ, ๐๐ฉ๐ง๐๐ฃ๐๐ฉ๐๐๐ฃ๐๐ ๐๐ฎ ๐๐๐๐๐ผ๐๐๐๐ฟ
From GDPR to PCI DSS, ISO 27001, SOC 2, GLBA, HIPAA, and SWIFT CSCF โ penetration testing is no longer optional. ๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป๐ ๐๐ผ๐ฟ๐น๐ฑ๐๐ถ๐ฑ๐ฒ ๐ฑ๐ฒ๐บ๐ฎ๐ป๐ฑ ๐ผ๐ฟ๐ด๐ฎ๐ป๐ถ๐๐ฎ๐๐ถ๐ผ๐ป๐ ๐ฝ๐ฟ๐ผ๐๐ฒ ๐๐ต๐ฎ๐ ๐๐ต๐ฒ๐ถ๐ฟ ๐ฑ๐ฒ๐ณ๐ฒ๐ป๐๐ฒ๐ ๐ต๐ผ๐น๐ฑ ๐ฎ๐ด๐ฎ๐ถ๐ป๐๐ ๐ฟ๐ฒ๐ฎ๐น-๐๐ผ๐ฟ๐น๐ฑ ๐๐ต๐ฟ๐ฒ๐ฎ๐๐.
๐๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ is the baseline. ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ is the destination. ๐ช๐ถ๐๐ต ๐ฅ๐๐๐๐๐ก๐ข๐๐, ๐๐ผ๐ ๐ด๐ฒ๐ ๐ฏ๐ผ๐๐ต.
#Pentesting #CyberSecurity #Compliance #ISO27001 #PCI #SOC2 #HIPAA #GLBA #GDPR #SWIFT #InfoSec