The New ISO 27002:2022—What Does It Mean for Your ISO 27001 ISMS?
The new ISO 27002:2022 makes significant changes to the control set that your ISO 27001 information security management system (ISMS) is probably based on. What does this mean for the ISO 27001...
View ArticleThe Value of Attributes in the New ISO 27002:2022
In the new ISO 27002:2022, each of the 93 controls is tagged with a series of attributes. What is the point of all this extra tagging? Doesn’t it just reintroduce complexity that restructuring...
View ArticleThe New ISO 27002:2022—What’s New with the Controls?
The new ISO 27002:2022 moves from 114 controls across 14 domains to 93 controls grouped into 4 themes. Does that mean you can stop executing 21 controls? Not likely! The change reflects...
View ArticleThe New ISO 27002:2022—What are “Themes” and Why are They Cool?
The new and upcoming changes to the ISO 27001 and ISO 27002 “gold standards” for cybersecurity are a big deal for organizations across our global industry that have achieved or are working...
View ArticleThe New ISO 27002:2022 — How Was It Developed?
The ISO 27001 and ISO 27002 “gold standards” for cybersecurity are both changing in 2022. The new ISO 27002:2022 version was released on February 15, 2022 and the draft amendment to ISO...
View ArticleWhat Does the New ISO 27002 Update Mean for You?
After eight years, ISO 27002:2022 is finally here. The changes are not just about the controls themselves, but also about making them easier to understand and apply. What does that mean for...
View ArticleDIB Orgs: Your SPRS Score, System Security Plan and POAMs Had Better Be for Real
One of the requirements for compliance with the US Department of Defense (DoD)’s current and future security program around CMMC 2.0 and NIST 800-171 is to submit an accurate score to the...
View ArticleContinuous Compliance for DIB Orgs: What Are Some Examples?
With the US Department of Defense (DoD) moving towards a “continuous compliance” model for NIST 800-171, how can SMBs in the defense industrial base (DIB) efficiently and effectively create...
View Article3 Inescapable Reasons Why DIB Orgs are Now Reliant on Their Compliance Programs
CMMC 2.0’s refocusing on NIST 800-171 as the compliance target for US defense industrial base (DIB) orgs that handle Controlled Unclassified Information (CUI) also comes with new attestation...
View ArticleCMMC 2.0 Compliance—What Will It Look Like at Level 1 or Level 2?
CMMC 2.0 takes the US defense industrial base (DIB) “back to the future” by refocusing cybersecurity and compliance efforts on NIST 800-171. This standard has been the target all along for...
View ArticleCMMC 2.0 Compliance—Here’s What to Focus on Now
Firms in the US defense industrial base (DIB) have seen their share of “regulatory fluctuations” in the past 18 months. The magnitude and pace of change—never mind the growing list of...
View ArticleContinuous Compliance—What is It and Why Should You (as a DIB Org) Care?
“Compliance” is too august and fraught a term to be labeled a buzzword—but lately there’s a lot of buzz around compliance, especially when the word “continuous” precedes it. What does...
View ArticleAre You Ready for the New ISO 27001:2022?
Like The Who sang back in the day, “The change it had to come. We knew it all along.” A change to the longstanding ISO 27001 control framework that was announced in 2018 has finally arrived...
View ArticleHow (Not) to Perfect Your ISO 27001 Information Security Management System in...
When Pivot Point Security decided to pursue ISO 27001 certification in 2015, we assumed it would be a slam dunk. After all, we had been one of the country’s top ISO 27001 consulting companies...
View ArticleWhat the New ISO 27001:2021 Release Will Mean to You
If your organization is ISO 27001 certified, you are likely aware that the International Organization for Standardization (ISO) is changing the structure of the ISO 27001/27002 control framework. This...
View ArticleDon’t “Over-Commit and Under-Deliver” on Your ISO 27001 Controls
With most cybersecurity frameworks, such as SOC 2 or NIST 800-171, the emphasis is on the controls, with all organizations being obliged to implement the same “one size fits all” control set. Many...
View ArticleISO 27001 Top Tip: Focus on Process, Not Controls
Organizations that are pursuing ISO 27001 certification often think that the standard is all about the controls. When you’ve implemented and documented all 114 controls in ISO 27001’s Annex A, you’re...
View ArticleThink Beyond ISO 27001 Certification While You’re Prepping for It
If your company is working towards ISO 27001 certification, you may be laser-focused on achieving that goal, and perhaps not worrying about what other cybersecurity and privacy efforts might need to...
View ArticleDon’t Rush Your ISO 27001 Certification
Most organizations pursue ISO 27001 certification because they are under pressure from clients, regulators and/or investors to prove they can protect sensitive data. Often, there’s time pressure as...
View ArticleISO 27701 Privacy Extension “Lessons Learned”: Data Mapping
The new ISO 27701 “certifiable extension” to ISO 27001 lets you add a Privacy Information Management System (PIMS) to your Information Security Management System (ISMS). Escalating data privacy...
View Article