The sadly neglected Risk Treatment Plan

 For some curious reason, the Statement of Applicability steals the limelight in the ISO27k world, despite being little more than a formality. Having recently blogged about the dreaded SoA, ’nuff said on that.Today I’m picking up on the SoA’s shy …

Read More >>

Infosec principles (Hinson tips)

Thinking about the principles underpinning information risk and security, here’s a tidy little stack of 44 “Hinson tips” – one-liners to set the old brain cells working this chilly mid-Winter morning:Address information confidentiality, integrity and a…

Read More >>

WANTED: a set of infosec principles we can all agree on

The SecAware corporate information security policy template incorporates a set of generic principles for information risk and security such as “Our Information Security Management System
conforms to generally accepted good security practices as descri…

Read More >>

People = More People

This quarter we grew our team by 25%, and we have on the docket to grow by another 25% next quarter adding another 50 people in the next three months. We’re super excited about our future, and the progress we’re making. Our team growth is a…

Read More >>

The Matrix, policy edition

Inspired by an insightful comment on LinkeDin from an SC 27 colleague on the other side of the world (thanks Lars!), I spent most of last week updating the SecAware security policy templates and ISO27k ISMS materials.The main change was to distinguish …

Read More >>