home.social

#securitymaturity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitymaturity, aggregated by home.social.

  1. Most organizations think their email security is solid until a phishing attack proves otherwise.

    This 4-level Email Security Maturity Model helps you assess where you stand, identify gaps, and move from basic controls to advanced, automated protection.

    A quick framework for IT leaders and security teams to strengthen defenses and reduce risk.

    #EmailSecurity #Cybersecurity #Infosec #Phishing #DMARC #MFA #DLP #ZeroTrust #SecurityMaturity #RiskManagement

  2. Most organizations think their email security is solid until a phishing attack proves otherwise.

    This 4-level Email Security Maturity Model helps you assess where you stand, identify gaps, and move from basic controls to advanced, automated protection.

    A quick framework for IT leaders and security teams to strengthen defenses and reduce risk.

    #EmailSecurity #Cybersecurity #Infosec #Phishing #ZeroTrust #SecurityMaturity #RiskManagement

  3. 🔐 Hot take: If your ISO 27001 Statement of Applicability still uses binary "Implemented / Not Implemented" for control status, you're losing valuable insight.

    We've adopted the N-P-L-F scale from ISO/IEC 15504 (now 33020):

    N – Not achieved (0–15%)
    P – Partially achieved (>15–50%)
    L – Largely achieved (>50–85%)
    F – Fully achieved (>85–100%)

    It turns the SOA from a checkbox exercise into a real maturity roadmap and auditors appreciate the transparency.

    How do you handle implementation status in your SOA? Binary, CMMI-style levels or something else entirely? 😅

    #ISO27001 #InfoSec #ISMS #GRC #Compliance #SecurityMaturity

  4. 🔐 Hot take: If your ISO 27001 Statement of Applicability still uses binary "Implemented / Not Implemented" for control status, you're losing valuable insight.

    We've adopted the N-P-L-F scale from ISO/IEC 15504 (now 33020):

    N – Not achieved (0–15%)
    P – Partially achieved (>15–50%)
    L – Largely achieved (>50–85%)
    F – Fully achieved (>85–100%)

    It turns the SOA from a checkbox exercise into a real maturity roadmap and auditors appreciate the transparency.

    How do you handle implementation status in your SOA? Binary, CMMI-style levels or something else entirely? 😅

    #ISO27001 #InfoSec #ISMS #GRC #Compliance #SecurityMaturity

  5. 🔐 Hot take: If your ISO 27001 Statement of Applicability still uses binary "Implemented / Not Implemented" for control status, you're losing valuable insight.

    We've adopted the N-P-L-F scale from ISO/IEC 15504 (now 33020):

    N – Not achieved (0–15%)
    P – Partially achieved (>15–50%)
    L – Largely achieved (>50–85%)
    F – Fully achieved (>85–100%)

    It turns the SOA from a checkbox exercise into a real maturity roadmap and auditors appreciate the transparency.

    How do you handle implementation status in your SOA? Binary, CMMI-style levels or something else entirely? 😅

    #ISO27001 #InfoSec #ISMS #GRC #Compliance #SecurityMaturity

  6. Immature product security isn’t just inefficient, it’s dangerous, & organizations can’t afford to treat it as an afterthought anymore.

    Learn more in our latest blog 👉 finitestate.io/blog/immature-p

    #ProductSecurity #CyberSecurity #IoTSecurity #DevSecOps #SecurityMaturity

  7. Immature product security isn’t just inefficient, it’s dangerous, & organizations can’t afford to treat it as an afterthought anymore.

    Learn more in our latest blog 👉 finitestate.io/blog/immature-p

    #ProductSecurity #CyberSecurity #IoTSecurity #DevSecOps #SecurityMaturity

  8. Nearly 90% organizations have begun embracing zero-trust security, but many still have a long way to go, according to a report by multinational technology company Cisco. #zeroTrust #cyberSecurity #Cisco #securityMaturity #securityOutcomes
    jpmellojr.blogspot.com/2023/11