The discomfort zone

Compliance is a concern that pops up repeatedly on the ISO27k Forum, just this  morning for instance. Intrigued by ISO 27001 Annex A control A.18.1.1 “Identification of applicable legislation and contractual requirements”, members generally ask wh…

Read More >>

Can I get my padrón online in Spain?

The padrón certificate is a handy multipurpose document you receive when you register with your local town hall in Spain. It can often be frustrating having to apply for it in person, so are you able to apply online instead?

Read More >>

Standards development – a tough, risky business

News emerged during June of likely further delays to the publication of the third edition of ISO/IEC 27001, this time due to the need to re-align the main body clauses with ISO’s revised management systems template (specfically, the 2022 edition of the…

Read More >>

Shout, shout, let it all out

Here’s an insightful and enjoyable way to explore your psyche and vent a little tension at the end of a tough month, week or day.First, find yourself a private space to watch Tears for Fears.Now shout, shout, let it all out: what are the things you cou…

Read More >>

What are “information assets”?

Control 5.9 in ISO/IEC 27002:2022 recommends an inventory of information assets that should be “accurate, up to date, consistent and aligned with other inventories”.  Fair enough, but what are ‘information assets’? What, exactly, are we suppo…

Read More >>

Authorised exemptions

Inspired by an exchange on the ISO27k Forum yesterday morning, I wrote and published a simple 2-page exemptions policy template for SecAware. In essence, after explaining what ‘exemptions’ are, the policy requires that they are authorised after du…

Read More >>