Quantcast
Channel: ISMS Archives - Pivot Point Security
Browsing index pages (82 articles)

The New ISO 27002:2022—What Does It Mean for Your ISO 27001 ISMS?

        The new ISO 27002:2022 makes significant changes to the control set that your ISO 27001 information security management system (ISMS) is probably based on. What does this mean for the ISO 27001...

View Article


The Value of Attributes in the New ISO 27002:2022

        In the new ISO 27002:2022, each of the 93 controls is tagged with a series of attributes. What is the point of all this extra tagging? Doesn’t it just reintroduce complexity that restructuring...

View Article


The New ISO 27002:2022—What’s New with the Controls?

        The new ISO 27002:2022 moves from 114 controls across 14 domains to 93 controls grouped into 4 themes. Does that mean you can stop executing 21 controls? Not likely! The change reflects...

View Article

The New ISO 27002:2022—What are “Themes” and Why are They Cool?

        The new and upcoming changes to the ISO 27001 and ISO 27002 “gold standards” for cybersecurity are a big deal for organizations across our global industry that have achieved or are working...

View Article

The New ISO 27002:2022 — How Was It Developed?

        The ISO 27001 and ISO 27002 “gold standards” for cybersecurity are both changing in 2022. The new ISO 27002:2022 version was released on February 15, 2022 and the draft amendment to ISO...

View Article


What Does the New ISO 27002 Update Mean for You?

        After eight years, ISO 27002:2022 is finally here. The changes are not just about the controls themselves, but also about making them easier to understand and apply. What does that mean for...

View Article

DIB Orgs: Your SPRS Score, System Security Plan and POAMs Had Better Be for Real

        One of the requirements for compliance with the US Department of Defense (DoD)’s current and future security program around CMMC 2.0 and NIST 800-171 is to submit an accurate score to the...

View Article

Continuous Compliance for DIB Orgs: What Are Some Examples?

        With the US Department of Defense (DoD) moving towards a “continuous compliance” model for NIST 800-171, how can SMBs in the defense industrial base (DIB) efficiently and effectively create...

View Article


3 Inescapable Reasons Why DIB Orgs are Now Reliant on Their Compliance Programs

        CMMC 2.0’s refocusing on NIST 800-171 as the compliance target for US defense industrial base (DIB) orgs that handle Controlled Unclassified Information (CUI) also comes with new attestation...

View Article


CMMC 2.0 Compliance—What Will It Look Like at Level 1 or Level 2?

        CMMC 2.0 takes the US defense industrial base (DIB) “back to the future” by refocusing cybersecurity and compliance efforts on NIST 800-171. This standard has been the target all along for...

View Article

CMMC 2.0 Compliance—Here’s What to Focus on Now

        Firms in the US defense industrial base (DIB) have seen their share of “regulatory fluctuations” in the past 18 months. The magnitude and pace of change—never mind the growing list of...

View Article

Continuous Compliance—What is It and Why Should You (as a DIB Org) Care?

        “Compliance” is too august and fraught a term to be labeled a buzzword—but lately there’s a lot of buzz around compliance, especially when the word “continuous” precedes it. What does...

View Article

Are You Ready for the New ISO 27001:2022?

            Like The Who sang back in the day, “The change it had to come. We knew it all along.” A change to the longstanding ISO 27001 control framework that was announced in 2018 has finally arrived...

View Article


How (Not) to Perfect Your ISO 27001 Information Security Management System in...

          When Pivot Point Security decided to pursue ISO 27001 certification in 2015, we assumed it would be a slam dunk. After all, we had been one of the country’s top ISO 27001 consulting companies...

View Article

What the New ISO 27001:2021 Release Will Mean to You

If your organization is ISO 27001 certified, you are likely aware that the International Organization for Standardization (ISO) is changing the structure of the ISO 27001/27002 control framework.  This...

View Article


Don’t “Over-Commit and Under-Deliver” on Your ISO 27001 Controls

With most cybersecurity frameworks, such as SOC 2 or NIST 800-171, the emphasis is on the controls, with all organizations being obliged to implement the same “one size fits all” control set. Many...

View Article

ISO 27001 Top Tip: Focus on Process, Not Controls

Organizations that are pursuing ISO 27001 certification often think that the standard is all about the controls. When you’ve implemented and documented all 114 controls in ISO 27001’s Annex A, you’re...

View Article


Think Beyond ISO 27001 Certification While You’re Prepping for It

If your company is working towards ISO 27001 certification, you may be laser-focused on achieving that goal, and perhaps not worrying about what other cybersecurity and privacy efforts might need to...

View Article

Don’t Rush Your ISO 27001 Certification

Most organizations pursue ISO 27001 certification because they are under pressure from clients, regulators and/or investors to prove they can protect sensitive data. Often, there’s time pressure as...

View Article

ISO 27701 Privacy Extension “Lessons Learned”: Data Mapping

The new ISO 27701 “certifiable extension” to ISO 27001 lets you add a Privacy Information Management System (PIMS) to your Information Security Management System (ISMS). Escalating data privacy...

View Article
Browsing index pages (82 articles)


Latest Images