Filter posts by category

ISO 27001

ISO 27001 Annex A 8.29

ISO 27001:2022 Annex A 8.29 Security testing in development and acceptance

When it comes to building software, the “build it now, fix it later” approach is a recipe for disaster. ISO 27001:2022 Annex A 8.29 exists to stop that bad habit in its tracks. This control mandates that you define and implement security testing processes throughout your entire development lifecycle. It’s not just about a final […]

ISO 27001:2022 Annex A 8.29 Security testing in development and acceptance Read More »

ISO27001 Clauses

ISO 27001 Clauses

The Core Requirements of ISO 27001 Clauses 4-10 The ISO/IEC 27001:2022 standard is divided into several sections, known as clauses, and appendices, known as annexes. To understand the requirements for achieving ISO 27001 certification, focus on clauses 4 through 10. Clauses 4-10 outline the specific requirements that an Information Security Management System (ISMS) must fulfil

ISO 27001 Clauses Read More »

ISO 27001 Clause 7.4

ISO 27001 Clause 7.4 Communication

ISO 27001 Clause 7.4 is about communication. It focuses on sharing key parts of your Information Security Management System (ISMS) with the right people. This helps everyone know their role in keeping data safe. What is ISO 27001 Clause 7.4? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the

ISO 27001 Clause 7.4 Communication Read More »

ISO 27001 Clause 7.3

ISO 27001 Clause 7.3 Awareness

ISO 27001 Clause 7.3 is all about making sure people know about information security. It states that everyone working for the company must know about the security policy and how they help the security system work well. This also includes knowing what could happen if they don’t follow the rules. What Is Awareness? This rule

ISO 27001 Clause 7.3 Awareness Read More »

ISO 27001 Clause 7.2

ISO 27001 Clause 7.2 Competence

ISO 27001 Clause 7.2 is about making sure that people who work on your company’s information security are good at their jobs. This means they have the right skills and experience. The goal of this rule is to ensure that your security team has the knowledge and training they need to do their work well.

ISO 27001 Clause 7.2 Competence Read More »

ISO 27001 Clause 7.1

ISO 27001 Clause 7.1 Resources

ISO 27001 Clause 7.1 is about making sure a company has the right resources to manage its information security system. This includes people, money, and tools. The rule states that a company must figure out what it needs and then provide it. This helps a company build, use, and improve its security system. What is ISO 27001

ISO 27001 Clause 7.1 Resources Read More »

ISO 27001 Clause 4.3

ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management System (ISMS)

ISO 27001 is a rulebook for keeping info safe. Clause 4.3 is a key part. It helps you decide what parts of your company to protect. This is called setting the scope. It’s super important to get the scope right. If you don’t, you might waste time and money. It’s like building a fence. You need

ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management System (ISMS) Read More »

ISO 27001 Clause 4.2

ISO 27001 Clause 4.2 Understanding The Needs And Expectations of Interested Parties

To meet ISO 27001 Clause 4.2, a company must understand the needs and expectations of interested parties. These are people or groups that have a stake in the company’s information security management system (ISMS). This is a vital step to ensure the ISMS works for everyone. What is ISO 27001 Clause 4.2? The latest version of

ISO 27001 Clause 4.2 Understanding The Needs And Expectations of Interested Parties Read More »