Jim
The ISO Review Podcast
The ISO Review Podcast is a production of SimplifyISO. In each episode, we share the latest International Standards Development, and is your resource for getting the most out of your management systems. Your podcast hosts are Howard Fox & Jim Moran. Howard is a Business Coach and Host of the Success InSight Podcast. Jim is an ISO Management System Professional, celebrating 30-plus years delivering ISO support.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Guidelines For The Assessment of Information Security Controls - Clause 6.2 Resourcing and Competence 12.03.2024 27:34
Howard and Jim chat about ISO/IEC TS 27008:2019 - Guidelines for the assessment of Information Security Controls - Clause 6.2 Reourcing and Competence. POINTS DISCUSSED What are the key takeaways from the discussion on clause 6.2, resourcing and competence? How does this standard help organizations to assess the effectiveness of their information security controls? What are the skills and competen...
ISO/IEC TS 27008:2019 - Overview of Information Security Control Assessments - Clauses 6.1.4 - 6.1.5. 27.02.2024 29:05
Howard and Jim chat about ISO/IEC TS 27008:2019 - Overview of Information Security Control Assessments - Clauses 6.1.4 - 6.1.5. POINTS DISCUSSED How does the process of obtaining permission to access all areas and controls play into the effectiveness of an information security audit? Why is it crucial for auditors to create a review checklist, and what should typically be included in this checklis...
ISO/IEC TS 27008:2019 - Overview of Information Security Control Assessments - Clauses 6.1.1 - 6.1.3 13.02.2024 29:44
Howard and Jim chat about ISO/IEC TS 27008:2019 - Overview of Information Security Control Assessments - Clauses 6.1.1 - 6.1.3. POINTS DISCUSSED What strategies can organizations employ to ensure that their procedures are not only being followed but are also working efficiently and effectively? How do supply chain contracts affect information security activities, and what role does software play i...
ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls - Clause 5_Background 30.01.2024 22:54
Howard and Jim chat about ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls - Clause 5_Background POINTS DISCUSSED What are the key takeaways from the discussion on ISO 27008 and its significance for organizations in terms of information security controls and guidelines? How do information security controls play a vital role in managing unacceptable risks and p...
ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls 05.12.2023 30:21
Howard and Jim chat about ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls. Points discussed include: How do the ISO 27008 and ISO 27001 standards work together to enhance information security within organizations? Why is it important for organizations to have good monitoring systems in place, and what are some key considerations for setting up effective mon...
Additional Observations and Benefits of Integrating an ISO 27001 Into an Existing ISO 9001 Quality Management System 21.11.2023 26:27
Howard and Jim chat about "Additional Observations and Benefits of Integrating an ISO 27001 Into an Existing ISO 9001 Quality Management System." Points discussed include: How can integrating ISO 27001 into an existing ISO 9001 system benefit an organization? What are the key differences between ISO 9001 and ISO 27001 in terms of structure and requirements? How can organizations effec...
Information Security in Supplier Contracts: ISO 27036 Part 2, Clause 7.5 - Supplier Termination Process 31.10.2023 27:43
Howard and Jim chat about ISO 27036-2, Clause 7.5 - Supplier Termination Process. Points discussed include: How important is it for organizations of all sizes to prioritize information security? What are some challenges organizations face when it comes to supplier relationship termination? How can ISO standards help organizations in managing their supplier relationships and information secur...
Information Security in Supplier Contracts: ISO 27036 Part 2, Clause 7.4 - Supplier Relationship Management Process 17.10.2023 27:06
Howard and Jim chat about ISO 27036-2, Clause 7.4 - Supplier Relationship Management Process. Points discussed include: The importance for organizations to have a process for managing supplier relationships in terms of information security. The potential risks or vulnerabilities that organizations may face when it comes to information security in the supply chain. What organizations can do t...
Information Security in Supplier Contracts: ISO 27036 Part 2, Clause 7.3 - Supplier Relationship Agreement 03.10.2023 21:17
Howard and Jim chat about ISO 27036-2, Clause 7.3 - Supplier Relationship Agreement Process. Points discussed include: How important it is for businesses to have supplier contracts that address information security? The key elements that should be included in an agreement to ensure information security. How can businesses effectively measure their suppliers' compliance with information...
Cybersecurity in Supplier Relationships: ISO 27036 Part 2, Clause 7.2 - Supplier Selection Process 19.09.2023 31:54
Howard and Jim chat about ISO 27036-2, Clause 7.2 - Supplier Selection Process. Points discussed include: How can organizations effectively plan their supplier relationships to mitigate information security risks? What are some real-life examples of information security breaches and their impact on organizations? Why is it important for organizations to communicate the importance of informa...
Cybersecurity in Supplier Relationships: ISO 27036 Part 2, Clause 7.1 Supplier Relationship Planning Process 29.08.2023 1:03:38
Howard and Jim chat about ISO 27036-2, Clause 7.1 - Supplier Relationship Planning Process. Points discussed include: How do the ISO 27036 standards help protect against potential risks and ensure personal safety? What are some potential legal and regulatory issues that suppliers should be aware of in relation to information security impacts? Why is it important for requirements and agreemen...
ISO 27036 Part 2 - Clause 6 Unpacked: Information security in supplier relationship management 15.08.2023 28:35
Howard and Jim chat about ISO 27036 Part 2 - Clause 6 - Information security in supplier relationship management Points discussed include: How does the ISO Review podcast contribute to the understanding and implementation of ISO standards in various industries? What are some practical steps that companies can take to ensure information security in supplier relationships? How has the globaliz...
Protecting Your Data: ISO 27036-1: Overview of Risks and Best Practices - Guidance for Supplier Relationships 01.08.2023 28:35
Howard and Jim chat about ISO 27036 Part I - Protecting Your Data: Overview of Understanding the Risks and Best Practices Guidance for Supplier Relationships. Points discussed include: Why is due diligence important when choosing suppliers? Why it's important to evaluate the security practices and capabilities of suppliers to make sure that they meet your information security requirement...
ISO 27008 Guidelines for Assessing Annex A Controls 18.07.2023 24:11
Howard and Jim chat about ISO 27008 Guidelines for Assessing Annex A Controls. Points discussed include: How many controls are required in ISO 27008? What are the seven steps outlined in ISO 27008 for measuring and assessing controls? How can ISO 27008 help organizations improve information security? What is the significance of continual improvement in information security controls? On Our...
Competence Requirements For Information Security Management Systems Professionals 27.06.2023 34:18
Howard and Jim chat about Competence Requirements For Information Security Management Systems Professionals. Points discussed include: What is the importance of communication and documentation in auditing firms for ISMS professionals? How can auditors prepare for an audit, and what information should they request from the organizations being audited? What ethics are involved in auditing and wh...
Achieving ISO 27001 Certification: The Path to Success 13.06.2023 28:46
Howard and Jim chat about the Path to ISO 27001 Certification. Points discussed include: What is ISO 27001 and why do some organizations need certification in it? Do most organizations need to be certified in ISO 27001 to bid on projects in the future? What is the process for achieving ISO 27001 certification? Why is formalizing and structuring information management important for organizations...
ISO 27001:2022, Annex A - Clause 8: Technical Controls 30.05.2023 24:34
Howard and Jim chat about ISO 27001, Annex A - Technical Controls. Points discussed include a review of the 14 controls in Clause 8: Annex A, Clause Eight, Technical Controls Number of controls:34 (8.1 to 8.34) On Our Next Episode The Path to ISO 27001 Certification - Find out the steps you'll need to take to become Certified to ISO 27001:2022! Next Steps - review your current situation...
ISO 27001:2022, Annex A - Clause 7: Physical Controls 17.05.2023 38:39
Howard and Jim chat about ISO 27001, Annex A - Physical Controls. Points discussed include a review of the 14 controls in Clause 7: Annex A, Clause Seven, Physical Controls Number of controls:14 (7.1 to 7.14) On Our Next Episode ISO 27001, Annex A - Clause 8 - Technology Controls. Next Steps - review your current situation against these controls to see if you can find a way to improve your Physi...
ISO 27001:2022, Annex A - Clause 6: People Controls 02.05.2023 32:06
Howard and Jim chat about ISO 27001, Annex A - People Controls. Points discussed include a review of the 8 controls in Clause 6: Annex A, Clause Six, People Controls Number of controls: 8 (6.1 to 6.8) On Our Next Episode ISO 27001, Annex A - Clause 7 - Physical Controls. Next Steps - review your current situation against these controls to see if you can find a way to improve your People controls...
ISO 27001:2022, Annex A - Clause 5: Organizational Controls 11.04.2023 36:56
Howard and Jim chat about ISO 27001, Annex A - Organization Controls. Points discussed include a review of the 37 controls in Clause 5: Annex A, Clause Five, Organizational Controls Number of controls: 37 (5.1 to 5.37) On Our Next Episode ISO 27001, Annex A - Clause 6 - People Controls. Next Steps - review your current practices against these controls required to see if you can find a way to impr...
Root Cause Analysis Considerations For Your ISO 27001 Information Security Management System 21.03.2023 24:22
Howard and Jim chat about Root Cause Analysis Considerations For Your ISO 27001 Information Security Management System. Points discussed include: Root Cause Analysis Considerations Determine the Cause of the Nonconformance Contributing Issues Ishikawa Fishbone Diagram Integration With Annex A 4-Column Integration Table showing the Ishikawa Fishbone and the 4 Annex A Clauses (See Link) Our Gift To...
Integration of an ISO 27001 into an existing ISO 9001 QMS 28.02.2023 28:00
Howard and Jim chat about the integration of an ISO 27001 into an existing ISO 9001 QMS. Points discussed include: ISO 9001 Quality Management Standard is the most prevalent in the world. It's been around since 1987 and there are over 2 million certificates worldwide in over 170 countries. Best Practice would be to integrate ISO 27001 into your existing ISO 9001 system (or any other Harmonize...
ISO 27001 Statement of Applicability Document 14.02.2023 29:32
Howard and Jim chat about the ISO 27001:2022 - Statement of Applicability (SoA) Items discussed include: The Statement of Applicability is required for ISO 27001 certification. It’s a statement that explains which Annex A security controls are — or aren’t — applicable to your organization’s Information Security Management System (ISMS). You can update your current ISO 27001 Statement of Applicabil...
ISO 27007 - Guidance for Information Security Management Systems Auditing 31.01.2023 30:20
Howard and Jim chat about ISO 27007 - Guidance for Information Security Management Systems Auditing. Items discussed include: Plan - Do - Check - Act Approach. Getting clients to ask their auditees if the procedure, the way it's been implemented, is getting them the results they want. The purpose of auditing is to see if you're getting the results you want. Part of the audit is to see i...
ISO 27005 - Managing Information Security Risks 20.12.2022 32:36
Howard and Jim chat about ISO 27005 - Managing Information Security Risks in this episode of the ISO Review Podcast. Items discussed include: Plan - Do - Check - Act Approach Identify the risk Analyze the naure and level of the risk Evaluate (low - medium - high ) the risk Select objectives and controls for the treatment of the risk Determine what is an acceptable level of the residual risk We l...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.