Jason Edwards

Framework - ISO 27001 (Cyber)

Education EN ↓ 71 episodes

The ISO/IEC 27001 Framework is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It provides a systematic approach to managing sensitive information through risk management, governance, and control implementation. At its core, ISO 27001 helps organizations protect the confidentiality, integrity, and availability of data—whether stored, processed, or transmitted—by aligning security practices with business objectives and regulatory requirements. The framework is built around a risk-bas...

Author

Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 46 — A.6.7–6.8 — Remote working; Event reporting 14.10.2025

A.6.7 establishes requirements for managing security in remote working arrangements, recognizing that homes, hotels, and public locations introduce different risks than controlled offices. For the exam, emphasize policy-led boundaries: approved devices, mandatory encryption, strong authentication, secure connectivity, and restrictions on local storage or printing. Controls must address physical co...

Episode 45 — A.6.5–6.6 — Responsibilities after termination/change; NDAs 14.10.2025

A.6.5 ensures that information security responsibilities remain clear when employment terminates or roles change. For the exam, emphasize time-bound deprovisioning of access, recovery of assets, revocation of credentials, and updates to authorization lists and distribution groups, all coordinated across HR, IT, Security, and managers. The control also expects continuity of obligations such as conf...

Episode 44 — A.6.3–6.4 — Awareness, education & training; Disciplinary process 14.10.2025

A.6.3 establishes the obligation to provide awareness, education, and training so that all personnel understand security policies, their responsibilities, and how to act in common scenarios. For the exam, differentiate universal awareness (policy, phishing hygiene, reporting lines) from role-based training for engineers, administrators, legal, and customer support. Programs should be periodic, mea...

Episode 43 — A.6.1–6.2 — Screening; Terms & conditions of employment 14.10.2025

A.6.1 requires appropriate background screening of candidates, contractors, and third-party users in accordance with relevant laws, regulations, and ethics, proportionate to risk and role sensitivity. For exam preparation, distinguish screening depth by role class: public-facing retail roles differ from privileged administrators or finance approvers. Typical elements include identity verification,...

Episode 42 — A.5 Integration Capstone — Pitfalls, auditor patterns, mappings 14.10.2025

This capstone episode synthesizes Annex A.5’s governance and organizational controls, highlighting how misalignments commonly appear in audits and how to map requirements to other frameworks. For the exam, recognize typical pitfalls: policies that are not enforced by procedures, role definitions that lack authority, supplier controls that stop at onboarding, and incident playbooks untested under p...

Episode 41 — A.5.37 — Documented operating procedures 14.10.2025

A.5.37 requires organizations to establish, document, and maintain operating procedures that guide consistent, controlled execution of security-relevant tasks. For the exam, remember that “documented” implies governed: procedures must identify purpose, scope, roles, prerequisites, inputs and outputs, step-by-step actions, acceptance criteria, and references to higher-level policies and standards....

Episode 40 — A.5.35–5.36 — Independent review; Compliance with policies/rules/standards 14.10.2025

A.5.35 requires independent reviews of information security to verify that management arrangements and controls remain suitable and effective. “Independent” means objective and free from conflicts—often performed by internal audit, corporate risk, or qualified external assessors. For the exam, tie this to governance: scope definition, criteria selection, evidence-based conclusions, and reporting t...

Episode 39 — A.5.33–5.34 — Protection of records; Privacy & PII protection 14.10.2025

A.5.33 mandates that records—authoritative evidence of activities performed—are protected so they remain authentic, reliable, and usable for as long as needed. For the exam, note the required controls: classification, retention rules, integrity safeguards, controlled access, and secure disposal. Records may include logs, audit trails, training attestations, incident reports, contracts, and design...

Episode 38 — A.5.31–5.32 — Legal/regulatory/contractual; Intellectual property rights 14.10.2025

A.5.31 requires organizations to identify and comply with all applicable legal, regulatory, and contractual requirements related to information security. For the exam, emphasize traceability: you need a maintained register of obligations mapped to controls, owners, jurisdictions, and evidence artifacts. Obligations can include data protection laws, sector regulations, export controls, breach notif...

Episode 37 — A.5.29–5.30 — Security during disruption; ICT readiness for BC 14.10.2025

A.5.29 focuses on maintaining information security when normal operations are disrupted, such as during disasters, severe outages, or crisis events. For the exam, remember that protection objectives do not pause; confidentiality, integrity, and availability must be sustained with alternate procedures, predefined authorities, and risk-based exceptions documented and time-boxed. A.5.30 strengthens t...

Episode 36 — A.5.27–5.28 — Learning from incidents; Collection of evidence 14.10.2025

A.5.27 requires organizations to institutionalize learning from incidents, transforming individual events into durable improvements. For the exam, emphasize that “learning” goes beyond a retrospective; it means capturing root causes, systemic contributors, and control gaps, then updating policies, baselines, training, and detection logic. The objective is to reduce recurrence probability and impac...

Episode 35 — A.5.25–5.26 — Event assessment/decision; Incident response 14.10.2025

A.5.25 establishes a disciplined mechanism to assess events and decide whether they constitute information security incidents, preventing alert fatigue and ensuring consistent prioritization. For exam purposes, distinguish between events, alerts, and incidents, and emphasize the need for defined criteria that consider asset criticality, data classification, attack indicators, and potential busines...

Episode 34 — A.5.23–5.24 — Use of cloud services; Incident mgmt planning & prep 14.10.2025

A.5.23 focuses on governing the use of cloud services so that risk treatment is consistent with enterprise policy and legal obligations. For the exam, explain that governance spans service selection, region strategy, identity and access models, data classification enforcement, shared responsibility interpretation, and exit planning. Cloud-specific risks include misconfigurations, uncontrolled prol...

Episode 33 — A.5.21–5.22 — ICT supply chain; Monitoring/review of supplier services 14.10.2025

A.5.21 extends supplier governance to the broader ICT supply chain, recognizing that products and services depend on multiple tiers of vendors, firmware, open-source components, and logistics. For exam readiness, emphasize mapping dependencies, verifying provenance, and assessing risks from compromised updates, counterfeit parts, end-of-life components, and opaque subprocessor chains. The control...

Episode 32 — A.5.19–5.20 — Supplier relationships; Supplier agreements 14.10.2025

A.5.19 establishes that supplier relationships must be governed to protect the organization’s information and services. For the exam, focus on risk-based segmentation of suppliers—by data sensitivity, service criticality, connectivity, and substitution difficulty—and on due diligence that assesses security posture before onboarding. This includes evaluating certifications, SOC reports, vulnerabili...

Episode 31 — A.5.17–5.18 — Authentication information; Access rights 14.10.2025

A.5.17 requires organizations to protect authentication information throughout its lifecycle, emphasizing creation, issuance, use, storage, and revocation. For exam purposes, distinguish between authentication factors (something you know, have, are) and the artifacts that embody them, such as passwords, tokens, private keys, and biometric templates. The control stresses proper strength, secrecy, a...

Episode 30 — A.5.15–5.16 — Access control; Identity management 14.10.2025

A.5.15 requires that access to information and other associated assets be limited to authorized users, processes, or devices, in accordance with business and security requirements. For the exam, focus on the principle of least privilege, segregation of duties, and policy-driven access criteria mapped to classification and risk. A.5.16 complements this with identity management, encompassing the ful...

Episode 29 — A.5.13–5.14 — Labelling of information; Information transfer 14.10.2025

A.5.13 builds on classification by requiring that information be labelled according to handling requirements. For the exam, understand that labels may be visual (document headers/footers, watermarks), metadata (embedded tags), or technical (container tags in data platforms). Correct labelling ensures that downstream controls—encryption policies, sharing restrictions, retention rules—can act automa...

Episode 28 — A.5.11–5.12 — Return of assets; Classification of information 14.10.2025

A.5.11 mandates that employees, contractors, and third parties return all organizational assets upon termination or change of role. For the exam, highlight that “assets” include devices, credentials, tokens, documents, and data copies in cloud storage or personal devices. The control reduces exposure by ensuring that access and material are promptly reclaimed, logged, and sanitized. A.5.12 require...

Episode 27 — A.5.9–5.10 — Asset inventory; Acceptable use 14.10.2025

A.5.9 requires an accurate, current inventory of information and other associated assets, including hardware, software, data sets, cloud resources, identities, and services. For exam purposes, stress that inventories must identify owners, classification, location, and lifecycle state so that risks and controls can be applied consistently. In modern environments, “asset” extends beyond physical dev...

Episode 26 — A.5.7–5.8 — Threat intelligence; Security in project management 14.10.2025

A.5.7 introduces threat intelligence as a structured capability to collect, analyze, and share information about adversaries, techniques, vulnerabilities, and emerging risks that could affect the organization. For the exam, remember that intelligence must be actionable—timely, relevant, and validated—so it can inform risk assessments, control tuning, and incident readiness. Sources can include com...

Episode 25 — A.5.5–5.6 — Contact with authorities; Special interest groups 14.10.2025

A.5.5 requires organizations to establish and maintain appropriate contact with relevant authorities, such as regulators, law enforcement, and national or sector Computer Security Incident Response Teams (CSIRTs). For the exam, note that readiness includes identifying which authorities are competent by jurisdiction and topic, documenting when and how to contact them, and assigning roles authorized...

Episode 24 — A.5.3–5.4 — Segregation of duties; Management responsibilities 14.10.2025

A.5.3 addresses segregation of duties (SoD), a foundational control that reduces fraud and error by distributing tasks and authorities among different people. For the exam, understand that SoD applies beyond finance to domains like privileged system administration, code deployment, and change approvals. Organizations must design processes so that no single individual can both initiate and approve...

Episode 23 — A.5.1–5.2 — Policies for InfoSec; Roles & responsibilities 14.10.2025

A.5.1 requires establishing a set of information security policies that provide direction and support consistent with business objectives and relevant laws and regulations. For the exam, remember the essentials: policies must be approved by management, communicated to the organization, reviewed at planned intervals, and supported by lower-level standards and procedures. A.5.2 complements this by r...

Episode 22 — Clause 9.3 + 10 — Management review; Nonconformity; Continual improvement 14.10.2025

Clause 9.3 requires top management to conduct reviews at planned intervals to ensure the ISMS remains suitable, adequate, and effective. For exam purposes, recognize the mandatory inputs: changes in internal and external issues, feedback from interested parties, performance metrics, audit results, risk and opportunity status, resource adequacy, and improvement opportunities. Clause 10 then defines...

Listen to the Framework - ISO 27001 (Cyber) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.