Yossy's Security & AI Lab _Global
Making Information Security Practical and Easy to Understand
This podcast shares practical insights on information security, privacy protection, corporate IT, and AI governance, based on real experience supporting small and mid-sized companies in Japan. Topics include ISMS (ISO/IEC 27001), AIMS (AI Management Systems), incident response, and responsible AI use — all explained from an operational, in-house perspective rather than theory alone. One unique focus of this podcast is Japan’s Privacy Mark (P-Mark), a Japanese privacy management system that is widely used in Japan but not well known internationally. In this podcast, I explain what P-Mark is,
Author
Yossy's Security & AI Lab _Global
Category
Podcast website
Latest episode
Jun 14, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
A Short Break Until September 14.06.2026 1:41
The English version of this podcast will be on a short break until the end of August while I focus on my CISA studies and several ongoing projects. During this time, I’ll be learning more about IT governance, risk management, auditing, internal controls, IPO readiness, and J-SOX. I’m also considering sharing my CISA learning journey and practical experiences in future episodes. My goal is to retur...
ISMS-05Understanding Your Organization (Clause 4.1) 10.06.2026 5:19
ISMS does not begin with policies, procedures, or templates. It begins with understanding your organization. In this episode, Yoshida explains Clause 4.1 — Understanding the Organization and Its Context , one of the most important foundations of an effective ISMS. Topics include: understanding your business and objectives identifying internal and external issues recognizing the risks that affect y...
AIMS-22. AI, Compliance, and Legal Considerations 07.06.2026 3:13
Many people worry about legal issues when using AI. For example: terms of service copyright personal data confidential information These topics may seem difficult. But the basic ideas are often simple. In this episode, we explain legal and compliance considerations for AI use in a practical way. You will learn: what to check before using AI common legal concerns simple ways to reduce risk 👉 Legal...
ISMS-04 What Does ISMS Protect? The Big Picture 03.06.2026 5:31
When people hear "ISMS," they often think of strict rules to stop data leaks. But actually, ISMS protects much more than just information. In this episode, Yoshida talks about the big picture of ISMS. What does it really protect? This is a great preparation before learning the actual ISO27001 rules. We hope this episode helps you ask: "What about our company?"
AIMS-21. AI Security Incidents: Lessons from Real Cases 31.05.2026 3:19
AI is becoming part of everyday work. At the same time, AI-related incidents are increasing. Many incidents do not start with hackers. They start with simple mistakes. For example: entering confidential information using incorrect AI output publishing content without review trusting AI too much In this episode, we look at common AI-related incidents and the lessons we can learn from them. 👉 AI in...
ISMS-03 What Makes ISMS Work Well? 27.05.2026 4:46
Many companies think ISMS is only about rules and documents. But in reality, successful companies focus on something different. They focus on operations that people can actually continue. In this episode, Yoshida talks about the common characteristics of companies that run ISMS well, even with small teams and limited resources. A practical and realistic discussion for corporate IT, management team...
AIMS-20. Does Everyone Need AI Training? 24.05.2026 5:25
Generative AI is no longer only for IT specialists. Today, employees across many departments — including sales, HR, accounting, and management — are already using AI in their daily work. That is why organizations now need more than just “AI tools.” They need responsible AI usage across the company. In this episode, A.9.2 Processes for Responsible Use of AI Systems from a practical and real-world p...
PMS-02 What Is an Incident? Where Is the Line? 20.05.2026 3:11
Many companies struggle with one question: “When does an event become an incident?” In this episode, we explain: The difference between events and incidents Common gray-zone cases Why reporting matters This is a practical guide for real PMS operation.
AIMS-19. Incident Management (A.8.2) 17.05.2026 3:14
AI incidents can happen in any organization. For example: sensitive data is entered wrong information is shared inappropriate content is published copyright issues occur These problems cannot be fully avoided. That is why Incident Management (A.8.2) is important in AIMS. In this episode, we explain simple first actions: 👉 Stop 👉 Check 👉 Report These steps help reduce damage and keep the situati...
PMS-01. What Does P-Mark Protect? (Overview) 13.05.2026 2:21
P-Mark (PMS) is not just about rules or documents. It is a system to continuously protect personal data. In this episode, we explain the core concept of PMS, why operations differ by company, and how it compares with ISMS in a simple way.
AIMS-18. Validation and Testing 10.05.2026 3:07
AI is useful, but it should not be used without checking. That is why Validation and Testing (A.6.2.4) is important in AIMS. This episode explains: 👉 what to check before using AI 👉 what to check after getting results You will learn a simple checklist: before using AI after using AI These checks help prevent: wrong information outdated content bias unsafe sharing 👉 AI is safe only when we check...
ISMS-02. Why ISMS Does Not Work 06.05.2026 2:40
Many companies have ISMS, but it does not work well. In this episode, we explain: four common problems why ISMS fails what companies should avoid The key point is simple. ISMS should be a system, not something one person runs.
AIMS-17. Design and Development: Data Handling (A.7.2) 03.05.2026 4:52
When you see an AI answer, do you think about the data behind it? AI results are affected by data. If the data has problems, the result may also have problems. For example: the data may be biased the source may be unclear the information may be old there may be copyright issues personal or sensitive data may be used In this episode, we talk about Design and Development: Data Handling (A.7.2) in AI...
ISMS-01. Where to Start ISMS 29.04.2026 3:08
Many companies start ISMS in the wrong way. They begin by making rules and documents. But this often causes problems. In this episode, we explain: a common mistake in ISMS why starting with rules does not work what companies should do first The key is simple. Start by understanding your company.
AIMS-16. AI Risk Assessment (A.6.3) 26.04.2026 3:29
I introduces new types of risks that are different from traditional IT. For example: data leakage incorrect outputs bias lack of transparency overtrust in AI These risks can feel unclear and scary. But when we identify and organize them, they become easier to manage. In this episode, we explain AI risk assessment (A.6.3) in a simple and practical way. 👉 If we understand AI risks, we can control t...
SEC-16. Where Should IPO Companies Start Security? 22.04.2026 2:45
Companies preparing for IPO often ask: “Where should we start with information security?” In this episode, we explain the first steps for building a security system in IPO preparation. We discuss: Building company-wide security awareness Creating basic security guidelines Listing information assets across departments Establishing security roles and committees This episode helps companies understan...
AIMS-15. Human Oversight (A.5.3) 19.04.2026 2:45
AI is powerful, but it is not perfect. That is why Human Oversight (A.5.3) is an important concept in AIMS. Human Oversight means: 👉 Do not rely on AI completely. Check AI results Review before use Make final decisions as a human These simple actions can reduce many risks. AI can make mistakes. It can use old data. It can misunderstand context. That is why humans must stay involved. In this episo...
AIMS-14. Transparency (A.5.2) 13.04.2026 3:19
Transparency is a key control in AIMS (ISO/IEC 42001). But what does it mean in practice? Transparency is simple. 👉 Make AI use visible and explainable. For example: Say when AI is used Show that humans check the results Be ready to explain how AI is used These small actions can build strong trust. In this episode, we explain A.5.2 Transparency from a practical point of view. You will learn how t...
AIMS-13. AIMS and ISMS — What’s the Difference? 29.03.2026 3:16
Many organizations already use ISMS (ISO/IEC 27001) to manage information security. But now, with the growing use of AI, another standard is emerging: AIMS (ISO/IEC 42001). So what is the difference? ISMS focuses on protecting information AIMS focuses on managing AI usage Even though their focus is different, their structure is very similar. Both use risk-based thinking, organizational management,...
SEC-15. Security for IPO Without Certification 25.03.2026 3:28
Many companies preparing for IPO ask the same question: “Do we need ISMS certification?” In many cases, certification is not strictly required. However, securities companies often recommend ISMS or the Privacy Mark because it makes the security structure easier to explain. In this episode, we discuss: What security structures IPO reviews focus on How to prepare company rules, records, and risk rev...
AIMS-12. Continuous Improvement and Communication 22.03.2026 3:20
Are AI rules something we create once and never change? In reality, AI technology and its usage change very quickly. In this episode, we explore continuous improvement and communication in AIMS (AI Management Systems). AIMS encourages organizations to improve their AI practices using the PDCA cycle : Plan Do Check Act This cycle helps organizations adapt to new risks, new technologies, and new exp...
SEC-14.Which Is Harder: ISMS or the Privacy Mark? 18.03.2026 3:23
Many companies ask the same question. “Which is harder: ISMS or the Privacy Mark?” Both are well-known certifications in Japan, but they are quite different. In this episode, we explain the differences in a simple way. The scope of ISMS and the Privacy Mark The difference between risk-based and rule-based systems Which part of the work becomes harder in real operations Why getting both certificati...
AIMS-11. Ethics and Fairness 15.03.2026 4:17
AI is a powerful and convenient tool. But convenience alone is not enough. When AI is used in business, questions about **ethics and fairness** become important. For example: - Could AI results contain bias? - Could someone be treated unfairly? - Could the result cause social problems? In this episode, we explain **ethics and fairness** in AIMS (AI Management Systems) in a simple and practical way...
SEC-13. What Is the Privacy Mark? 11.03.2026 5:09
“What exactly is the Privacy Mark?” In Japan, the Privacy Mark (P-Mark) is one of the most well-known certifications related to information security. But many people still wonder how it differs from ISMS. In this episode, we explain the key characteristics of the Privacy Mark system in simple terms. The Privacy Mark is based on Japan’s Personal Information Protection Law , and focuses specifically...
AIMS-10. Human-in-the-loop 08.03.2026 5:49
Generative AI is powerful. But many people still feel a quiet concern: “Can we really trust AI with important decisions?” In this episode, we talk about Human-in-the-loop — a simple but essential idea in AIMS. AI should not work alone. A human must stay inside the decision process. Why AI can make confident mistakes What “Human-in-the-loop” really means Why human involvement is not a brake, but a...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.