ISO International Management System Institute: Recent Episodes

Jim

International Management System Institute Review

View Details

Welcome back to another episode of the ISO Review Podcast, brought to you by Simplify ISO! This week, Howard Fox and Jim Moran kick off a brand new series diving deep into the world of ISO/IEC 27008—the essential guidelines for assessing information security controls.

In today’s episode, we set the stage by exploring the structure and background of ISO 27008, including its key sections and practical annexes for technical and cloud service assessments. Jim emphasizes the need for competent auditors, objective assessments, and documented improvements that drive real value for organizations—reminding us that having procedures is not enough; they must be properly implemented and continually improved.

Whether you’re a newcomer to ISO management systems or a seasoned pro, this series is designed to help you make sense of technical control assessments, understand compliance requirements, and ensure you’re protecting client, supplier, and employee information with the highest standards.

As always, you’ll find links to resources and ways to connect with Jim and Howard in the show notes. Grab your coffee, settle in, and get ready for a foundational look at information security management!

DISCUSSION

00:00 Understanding ISO 27008 Assessments

05:58 "Information Security Control Overview"

07:24 "Effective Implementation of Controls"

12:39 "Ensuring Objective Audit Practices"

16:40 Ensuring Effective Security Assessments

18:10 ISO 27001 Implementation Insight

21:45 Prioritizing Information Security Risk Mitigation

25:56 Integrated Management System Audit

31:04 "ISO Review Podcast Updates"

NEXT STEPS

We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

ISO 27008, Information Security Controls, Information Security Management System, ISO Review Podcast, SimplifyISO, Podcast

ISO27008 #InformationSecurityControls #InformationSecurityManagementSystem #ISOReviewPodcast #SimplifyISO #Podcast

View Details

Welcome back to another insightful episode of the ISO Review Podcast, brought to you by Simplify ISO! This week, Jim and Howard dive deeper into the intersection of artificial intelligence and ISO risk management, building on their previous discussion. With Jim sharing wisdom from over three decades in ISO support, and Howard adding his expertise with AI tools, the conversation explores practical ways organizations can leverage AI to streamline ISO 9001 processes—especially when it comes to identifying, analyzing, and mitigating risks.

DISCUSSION

00:00 AI & Risk Management Insights

05:23 "ISO 9001: Context & SWOT Guide"

06:51 Home Health Care SWOT Analysis

13:13 "Determining ISO 9001 Risks"

14:28 Risk Assessment and Mitigation Strategies

18:19 Risk Determination and ISO 31000

23:04 "Checklist for Safer Operations"

28:12 AI Enhancing Risk Assessment Expertise

30:09 Using AI for Webinar Creation

NEXT STEPS

We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

Artificial Intelligence, AI, SWOT Analysis, Information Security Management System, ISO Review Podcast, SimplifyISO, Podcast

ArtificialIntelligence #AI #SWOTAnalysis #InformationSecurityManagementSystem #ISOReviewPodcast #SimplifyISO #Podcast

View Details

Welcome back to another episode of the ISO Review Podcast, brought to you by Simplify ISO! This week, Jim Moran and Howard Fox dive deep into the essentials of assessing information security controls in line with ISO 27008.

Building on last week’s introduction, Jim Moran shares his expertise, highlighting the critical steps in reviewing and auditing controls from Annex A of ISO 27001, gathering evidence, and ensuring objectivity through well-structured assessment methodologies.

Whether you’re running a large organization or a small business, you’ll find practical tips for planning effective audits, resourcing your team, and leveraging checklists and flowcharts to enhance information security. Tune in for a comprehensive overview, actionable advice, and real-world examples designed to help you get the most out of your management systems and stay ahead in the ever-challenging world of information security.

DISCUSSIOON

00:00 Information Security Control Assessments

05:00 "Assessment Tips and Tools"

07:17 Checklist Methodology and Evidence Gathering

12:38 Cybersecurity Auditing & Penetration Testing

15:19 Privacy Compliance in Home Care

18:33 ISO 27002 Training Importance

23:24 Auditor Roles and System Strengthening

24:58 Audit Purpose: Beyond Procedure Compliance

29:33 "Linking Risk to Audit Results"

33:09 ISO Podcast Episode Wrap-Up

NEXT STEPS

We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

ISO 27008, Information Security Controls, Information Security Management System, ISO Review Podcast, SimplifyISO, Podcast

ISO27008 #InformationSecurityControls #InformationSecurityManagementSystem #ISOReviewPodcast #SimplifyISO #Podcast

View Details

Welcome back to the ISO Review Podcast, your trusted resource for the latest in international standards and maximizing your management systems. In this episode, hosts Jim and Howard dive into one of the most requested topics in the ISO world: risk and opportunity management. Jim draws from his 33 years of experience to share practical strategies for strengthening risk identification, sharpening evaluation tools, and, most importantly, embedding risk awareness deep into your organization’s culture.

The conversation takes a timely turn by exploring how artificial intelligence can supercharge your ISO management system, from streamlining risk analysis to making the most of your internal audits. Jim offers actionable tips, real-life examples, and even introduce techniques like flowcharting and the PESTLE analysis for a fresh perspective on spotting potential pitfalls and unlocking hidden opportunities.

DISCUSSION

00:00 Strengthening Risk and Opportunity Management

04:18 Embedding Risk in Internal Audits

10:27 Balancing Risks with Opportunities

13:19 "Everyone Manages Risk"

15:23 The Complexity of Small Changes

21:02 Risk Mitigation: Remove, Replace, Reduce

22:14 Flowchart-Driven Risk Management

27:01 AI's Impact on Risk Identification

28:40 Podcast Wrap-Up and Resources

NEXT STEPS

We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

Artificial Intelligence, AI, PESTLE analysis, Information Security Management System, ISO Review Podcast, SimplifyISO

ArtificialIntelligence #AI #PESTLEanalysis #InformationSecurityManagementSystem #ISOReviewPodcast #SimplifyISO

MUSIC
Think Different by Scott Holmes Music - https://scottholmesmusic.com

View Details

Click here to learn about our new DIY ISO 9001 program using AI

Welcome to the ISO Review Podcast. In this episode, Jim and Howard chat about the upcoming changes to ISO 9001, offering listeners an exclusive sneak peek at the new Draft International Standard set to shape quality management systems worldwide.

DISCUSSION

00:00 Global Reach of ISO 9001

05:55 ISO 9001 Update Preview

07:01 ISO Draft to International Standard Process

12:42 Quality Management Standards Differentiation

14:56 Distinguishing Risks and Opportunities Guidance

17:46 Focus on ISO Standards Clause 8

23:24 Internal Audit Program Essentials

26:12 "Streamlining ISO for Cost Efficiency"

32:59 "Podcast Wrap-Up and Links"

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website.

Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Click here to get Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

ISO 9001, Information Security, DIY ISO, AI Prompts, Online Forms, ISO Certification, SimplifyISO, ISO Review Podcast

ISO9001 #InformationSecurity #DIYISO #AIPrompts #OnlineForms #ISOCertification, SimplifyISO #ISOReviewPodcast

MUSIC CREDIT

108 52nd Street Music by TOOONE from Pixabay

View Details

Click here to learn about our new DIY ISO 9001 program using AI .

Welcome back to the ISO Review Podcast. In this episode, hosts Jim Moran and Howard Fox are joined by special guest Dejan Kosutic, CEO of Advisera.

Dejan is a renowned cybersecurity expert for ISO 27001. He is passionate about making compliance accessible. Dejan and Jim discuss how to use Artificial Intelligence (AI) to enhance your Information Security Management System (ISMS).

DISCUSSION

  1. AI and ISO 27001: Use cases for integrating AI into ISO 27001 compliance and information security.
  2. AI Accessibility: It’s now much easier for non-experts to build AI-based tools internally due to simplified technology.
  3. Security Concerns: Privacy and accuracy as major concerns when using AI for information security.
  4. The Changing Role of Security Professionals: AI will allow consultants and security managers to focus less on routine tasks and more on managing change and people.
  5. Change Management: Resistance to change within organizations and how AI might reduce this resistance by personalizing and democratizing information.
  6. AI for Learning and Development: AI can personalize training and generate relevant educational content for employees at different levels.
  7. Human Oversight: With AI producing vast amounts of information, Jim emphasized the importance of curating and interpreting this data.
  8. Career Development and AI: Dan mentioned that junior consultants are now able to advance much more quickly using AI, but that entry-level tasks are disappearing.
  9. Future-Proofing Your Career: Both Jim and Dan agreed that embracing AI is essential to staying relevant.

NEXT STEPS

We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

Click here to learn more about Dejan Kosutic

Advisera: https://advisera.com/
LinkedIn: https://www.linkedin.com/in/dejankosutic/
YouTube: https://www.youtube.com/@DejanKosutic

KEYWORDS

Dejan Kosutic, Advisera, Information Security Management System, ISO Review Podcast, SimplifyISO

DejanKosutic #Advisera #InformationSecurityManagementSystem #ISOReviewPodcast #SimplifyISO

MUSIC
Think Different by Scott Holmes Music - https://scottholmesmusic.com

View Details

Click here to learn about our new DIY ISO 9001 program using AI

Welcome back to the ISO Review Podcast, your trusted source for the latest in international standards development and practical tips on getting the most out of your management systems. In this episode, hosts Jim Moran and Howard Fox are joined by special guest Michael Kent Hart, the founder and CEO of Human.ca, who brings over 40 years of expertise in quality management and organizational excellence.

Mike's explanation of his work: https://human.ca/conscious-human-intention-in-the-workplace/

DISCUSSION

  1. How did Michael Hart’s introduction to Appreciative Inquiry shape his approach to positive intention in the workplace?
  2. In the Vermont hospital example, what differences did staff notice when using Appreciative Inquiry versus traditional problem-solving methods?
  3. How can focusing on what works well in an organization, rather than on problems, transform the energy and engagement of teams?
  4. What are the key differences between traditional cause-and-effect (Ishikawa) diagrams and the Opportunity Tree discussed in this episode?
  5. How did Michael Hart blend process reengineering and Appreciative Inquiry in his work with the Trinidad and Tobago government? What were the outcomes?
  6. Discuss the concept behind the SIBLING methodology. How does it differ from Lean and Six Sigma approaches?
  7. Why might traditional management system tools, like those promoted by ASQ, be seen as limiting compared to the positive intention approaches discussed here?
  8. What role does leadership play in sustaining a culture of positive intention within ISO management systems?
  9. Reflecting on the British Airways example: How did the shift from solving a single problem to pursuing the ‘ultimate customer experience’ impact organizational improvement efforts?

NEXT STEPS

We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

Click here to learn more about Michael Hart

KEYWORDS

Michael Kent Hart, Conscious Human Intention in the Workplace, Appreciative Inquiry, Quality Management System, Root Cause Analysis, ISO Review Podcast, SimplifyISO

ConsciousHumanIntentionintheWorkplace #AppreciativeInquiry #QualityManagement System #RootCauseAnalysis #ISOReviewPodcast #SimplifyISO

MUSIC
Think Different by Scott Holmes Music - https://scottholmesmusic.com

View Details

Click here to learn about our new DIY ISO 9001 program using AI

Welcome to the ISO Review Podcast. In this episode, Howard and Jim discuss an innovative approach to traditional root cause analysis inspired by the work of Michael Kent Hart. In this approach, there is a shift in focus from traditional root cause analysis and blame to a more positive, future-focused strategy centered on “intention in the workplace.”

Mike's explanation of his work: https://human.ca/conscious-human-intention-in-the-workplace/

DISCUSSION

  1. Introduction of Root Cause Analysis and Corrective/Preventive Action in ISO 9001

  2. The ongoing importance and function of corrective actions in management systems

  3. Turning Root Cause Analysis on Its Head: Intention-Based Approach

  4. Introduction of alternative approach inspired by Mike Hart’s work

  5. Focus on positive outcomes rather than negative issues

  6. Business Impact of Errors and the Importance of Process Improvement

  7. Mathematical impact of errors on profit margins

  8. Effects of errors on morale and productivity
  9. The link between reducing errors and organizational performance

  10. Case Study Example: British Airways & The Customer Experience

  11. Traditional root cause approach: problem-focused

  12. Intention-based approach: Creating the “ultimate customer experience”

  13. Implementation of Intention in Corrective Actions

  14. Shifting from blame and failure to purpose and growth

  15. Vision-Guided System Improvement

  16. The power of envisioning a future, ideal state for processes

  17. Encouragement of cross-functional teams and broad participation
  18. Role of top management

  19. Intentionality, Engagement, and Psychological Safety

  20. Intention as a driver of open communication and team engagement

  21. The importance of psychological safety and fear reduction
  22. Creating a learning culture & Ensuring future state improvements

  23. Next Steps and Future Episode Plans

  24. Proposal to interview Mike Hart on a future episode

NEXT STEPS

We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website.

Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Links to Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

Click here to learn more about Michael Hart, Founder and CEO of HUMAN - https://human.ca/about/

KEYWORDS

Quality Management System, Root Cause Analysis, ISO Review Podcast, SimplifyISO

View Details

Click here to learn about our new DIY ISO 9001 program using AI

Welcome to the ISO Review Podcast. In this episode, Howard and Jim continue with a video series designed to help organizations simplify the process of ISO 9001 certification, using a do-it-yourself approach.

Jim shares the journey behind creating the Simplify ISO platform—a user-friendly, cost-effective solution designed for small to mid-sized businesses looking to efficiently implement, maintain, and get certified without the headache. You'll hear how the platform addresses common pain points like document control, nonconformance management, and audit scheduling—all with the help of AI-driven tools and step-by-step guidance.

Don’t forget to check out the accompanying video on the Simplify ISO website and YouTube Channel for a complete visual walkthrough!

DISCUSSION

  1. The three main “thorns in the side” for people managing ISO management systems?
  2. How has the requirement for tracking document revisions in ISO standards changed since 2015, and how does the Simplify ISO tool support current requirements?
  3. What are some benefits of automating document control and version management in an ISO management system?
  4. Why is it important to properly document and complete non-conformances?
  5. What role does AI play in the “do it yourself” approach for building an ISO management system?
  6. How can organizations use the internal audit checklist and action sheets to ensure findings are properly tracked and addressed?
  7. What are the customizable features within the Simplify ISO tool when it comes to tracking non-conformances and audit findings?
  8. What is the importance of linking audit findings to the non-conformance system, and why this is often a challenge for organizations?
  9. How does the tool’s built-in notification system help users stay on top of corrective actions and non-conformance closure deadlines?
  10. Reflecting on the “help pages” and AI prompt examples shared, how might using these resources accelerate and enhance the ISO implementation process for a company?

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website.

Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Click here to get Conformance1's free online Gap Checklists:
ISO 9001 - https://conformance1.com/iso9001-gap-assessment-register/
ISO 27001 - https://conformance1.com/iso-27001-gap-checklist-dashboard/

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

Information Security, DIY ISO, AI Prompts, Online Forms, ISO Certification, ISO Review Podcast, SimplifyISO, Podcast

InformationSecurity #DIYISO #AIPrompts #OnlineForms #ISOCertification #ISOReviewPodcast #SimplifyISO #Podcast

View Details

Click here to learn about our new DIY ISO 9001 program using AI

Welcome to the ISO Review Podcast. In this episode, Howard and Jim continue with a video series designed to help organizations simplify the process of ISO 9001 certification, especially if you're considering a do-it-yourself approach.

With more than three decades of ISO consulting experience, Jim shares the journey behind creating the Simplify ISO platform—a user-friendly, cost-effective solution designed for small to mid-sized businesses looking to efficiently implement, maintain, and get certified without the headache. You'll hear how the platform addresses common pain points like document control, nonconformance management, and audit scheduling—all with the help of AI-driven tools and step-by-step guidance.

Whether you're a solo entrepreneur, a quality professional looking to branch out, or a business owner ready to take the plunge into ISO certification, this episode offers valuable tips, real-world examples, and a guided look at the Simplify ISO system in action.

Don’t forget to check out the accompanying video on the Simplify ISO website and YouTube Channel for a complete visual walkthrough!

DISCUSSION

00:00 "ISO Review Podcast Overview"

05:25 "Exploring the World of ISO Training"

06:55 "PowerPoint Tips & WordPress Potential"

10:28 ISO Certification Challenges: Key Areas

14:20 Career Advancement through Certification

17:48 "End-to-End Process Mapping Guide"

22:41 ISO 9001 Clause 4 Guidance

26:46 Personalized System Implementation Solution

30:09 "AI's Role in ISO Certification"

33:52 "Customer-Driven Platform Evolution"

35:49 ISO Certification Overview Series

LEARN MORE

Click here to try Conformance1's free online ISO 9001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimwill continue the live demonstration of the Do-It-Yourself (DIY) building of an ISO Management System using Artificial Intelligence (AI) to facilitate the completion of the standards in the sections. We'll focus further on the implementation of DIY ISO Management System.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website.

Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

Information Security, DIY ISO, AI Prompts, Online Forms, ISO Certification, ISO Review Podcast, SimplifyISO, Podcast, Podcast Interview

InformationSecurity #DIYISO #AIPrompts #OnlineForms #ISOCertification #ISOReviewPodcast #SimplifyISO #Podcast #PodcastInterview

View Details

Click here to learn about our new DIY ISO 9001 program using AI

Welcome to the ISO Review Podcast. In this episode, Howard and Jim kick off a special new video series designed to help organizations simplify the process of ISO 9001 certification, especially if you're considering a do-it-yourself approach.

With more than three decades of ISO consulting experience, Jim shares the journey behind creating the Simplify ISO platform—a user-friendly, cost-effective solution designed for small to mid-sized businesses looking to efficiently implement, maintain, and get certified without the headache. You'll hear how the platform addresses common pain points like document control, nonconformance management, and audit scheduling—all with the help of AI-driven tools and step-by-step guidance.

Whether you're a solo entrepreneur, a quality professional looking to branch out, or a business owner ready to take the plunge into ISO certification, this episode offers valuable tips, real-world examples, and a guided look at the Simplify ISO system in action. Plus, Howard and Jim preview what's coming up in future episodes, including practical demonstrations of building your quality management system and navigating the certification process.

Don’t forget to check out the accompanying video on the Simplify ISO website and YouTube Channel for a complete visual walkthrough!

DISCUSSION

05:25 "Exploring the World of ISO Training"

06:55 "PowerPoint Tips & WordPress Potential"

10:28 ISO Certification Challenges: Key Areas

14:20 Career Advancement through Certification

17:48 "End-to-End Process Mapping Guide"

22:41 ISO 9001 Clause 4 Guidance

26:46 Personalized System Implementation Solution

30:09 "AI's Role in ISO Certification"

33:52 "Customer-Driven Platform Evolution"

35:49 ISO Certification Overview Series

LEARN MORE

Click here to try Conformance1's free online ISO 9001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimwill continue the live demonstration of the Do-It-Yourself (DIY) building of an ISO Management System using Artificial Intelligence (AI) to facilitate the completion of the standards in the sections.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website.

Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube.

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, Inc.

KEYWORDS

Information Security, DIY ISO, AI Prompts, Online Forms, ISO Certification, ISO Review Podcast, SimplifyISO, Podcast, Podcast Interview

InformationSecurity #DIYISO #AIPrompts #OnlineForms #ISOCertification #ISOReviewPodcast #SimplifyISO #Podcast #PodcastIntervi

View Details

Howard and Jim discuss the ISO/IEC 42001 AI management system standard, Annex C (Potential AI-related organizational objectives and risk sources) and D (Use of the AI management system across domains or sectors).

POINTS DISCUSSED

Annex C

  1. Explanation of Annex C
  2. Objectives
  3. Risk Sources

Annex D

  1. Explanation of Annex D
  2. Integration of AI management system with other management system standards

Looking Ahead

Preview of next episode, where Jim will walk the listerner through a Do-It-Yourself (DIY) building of an ISO Management System using Artificial Intelligence (AI) to facilitate the completion of the standards themselves in the sections.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimwill facilitate a live demonstration that walk the listerner through a Do-It-Yourself (DIY) building of an ISO Management System using Artificial Intelligence (AI) to facilitate the completion of the standards themselves in the sections.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex C, Annex D, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexC #AnnexD #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #PodcastInterview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B.10 - Third-party and customer relationships.

POINTS DISCUSSED

  1. Explanation of what Clause B.10 - Third-party and customer relationships covers
  2. Objective
  3. Allocating responsibilities
  4. Suppliers
  5. Customers
  6. Looking Ahead - Preview of next episode focusing on Annex C (Potential AI-related organizational objectives and risk sources), and Annex D (Use of the AI management system across domains or sectors).

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex C (Potential AI-related organizational objectives and risk sources), and Annex D (Use of the AI management system across domains or sectors)

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #PodcastInterview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B.9 - Use of AI systems.

POINTS DISCUSSED

  1. Explanation of what Clause B.9 covers: “Use of AI systems”
  2. Key Requirements and Concepts in Clause B.9
  3. Real-World Applications & Analogies
  4. Internal vs. External AI Models in Organizations
  5. Human Oversight & Decision Support
  6. Integrating AI with Risk Management (Clause 6 and Beyond)
  7. Invitation to Use ISO 42001 Standard and AI-Driven Tools
  8. Looking Ahead - Preview of next episode focusing on Annex B.10 (third-party and customer relationships), and future content on annexes C and D.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B (Implementation Guidance for Artificial Intelligence Controls):

  • Clause B.10 - Third-party and customer relationships

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #PodcastInterview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B.8 - Information for interested parties.

POINTS DISCUSSED

  1. Objective of ISO 42001, Annex B.8 - Information for interested parties.
  2. System documentation and information for users
  3. External reporting
  4. Communication of incidents
  5. Information for interested parties

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B (Implementation Guidance for Artificial Intelligence Controls):

  • Clause B.9 - Use of AI systems
  • Clause B.10 - Third-party and customer relationships

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #PodcastInterview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B.7 - Data for AI systems.

POINTS DISCUSSED

  1. Objective of ISO 42001, Annex B.7 - Data for AI systems
  2. Data for development and enhancement of AI system
  3. Acquisition of data
  4. Quality of data for AI systems
  5. Data provenance
  6. Data preparation

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B (Implementation Guidance for Artificial Intelligence Controls):

  • Clause B.8 - Information for interested parties.
  • Clause B.9 - Use of AI systems
  • Clause B.10 - Third-party and customer relationships

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B.6 - AI system life cycle

POINTS DISCUSSED

  1. Overview of ISO 42001, Annex B.6: Implementation Guidance for Artificial Intelligence Controls
  2. Management guidance for AI system development
  3. AI system life cycle
  4. AI system requirements and specification
  5. Documentation of AI system design and development
  6. AI system verification and validation
  7. AI system deployment
  8. AI system operation and monitoring
  9. AI system technical documentation
  10. AI system recording of event logs

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B (Implementation Guidance for Artificial Intelligence Controls), Clause B.7, Data for AI systems.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B (Implementation Guidance for Artificial Intelligence Controls), Clause B.5.

POINTS DISCUSSED

  1. Overview of ISO 42001, Annex B: Implementation Guidance for Artificial Intelligence Controls
  2. Clause B5 and Impact Assessments
  3. High-Level Management System Structure
  4. Inputs, Process, Outputs
  5. Risks and Legal Considerations
  6. Impact Assessment Elements
  7. Retention and Documentation
  8. Human and Governance Consideration
  9. Security and Risk Management
  10. AI's Growing Role and Environmental Impact

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B (Implementation Guidance for Artificial Intelligence Controls), Clause B.6.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about ISO 42001, the world's first artificial intelligence management system International standard. In this episode they discuss Annex B (Implementation Guidance for Artificial Intelligence Controls), Clauses B.1 - B.4.

POINTS DISCUSSED

  1. Overview of ISO 42001, Annex B: Implementation Guidance for Artificial Intelligence Controls
  2. Annex B, Clause B.1 – Implemenation Guidance
  3. Annex B, Clause B.2 – Policies Related to Artificial Intelligence
  4. Annex B, Clause B.3 – Internal Organization
  5. Annex B, Clause B.4 – Resource Documentations

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B (Implementation Guidance for Artificial Intelligence Controls), Clauses B.5.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex B, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexB #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: ISO 42001, the world's first artificial intelligence management system International standard. In this episode we discuss Annex A (Controls), Claues A.7 - A.10

POINTS DISCUSSED

  1. Overview of ISO 42001 Annex A Controls
  2. Annex A Control A.7 – Data for AI Systems
  3. Annex A Control A.8 – Information for Interested Parties of AI Systems
  4. Annex A Control A.9 – Use of AI Systems
  5. Annex A Control A.10 – Third-Party and Customer Relationships

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex B Controls

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex A Controls, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexAControls #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: ISO 42001, the world's first artificial intelligence management system International standard. In this episode we discuss Annex A Controls, A.1 - A.6

POINTS DISCUSSED

  1. Overview of ISO 42001 Annex A Controls
  2. Annex A Control A.2 – Policies Related to AI
  3. Annex A Control A.3 – Internal Organisation
  4. Annex A Control A.4 – Resources for AI Systems
  5. Annex A Control A.5 – Assessing Impacts of AI Systems
  6. Annex A Control A.6 – AI System Life Cycle

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex A Controls, A.7 - A.10 and B (Implementation Guidance).

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Annex A Controls, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #AnnexAControls #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: ISO 42001, the world's first artificial intelligence management system International standard. In this episode we discuss Clause 10, Improvement

POINTS DISCUSSED

  1. Discussion of Clause 10: Improvement
  2. Details on Continual Improvement Processes
  3. Internal Audit Process
  4. Stakeholder and Interested Party Involvement
  5. Risk-Based Thinking Approach
  6. Implementation Challenges
  7. Post-Implementation Review
  8. Developing a Culture of Continual Improvement

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Annex A (Reference Control Objectives and Controls) and B (Implementation Guidance).

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO #Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: ISO 42001, the world's first artificial intelligence management system International standard. In this episode we discuss Clause 9, Performance Evaluation.

POINTS DISCUSSED

  1. Understanding ISO 42001
  2. Artificial Intelligence and Risk Assessment
  3. Internal Audits and ISO Standards
  4. Performance Evaluation
  5. Implementation Challenges
  6. Management Review Importance
  7. Continual Improvement
  8. Training and Skill Development
  9. Future of AI Systems in ISO
  10. Real-World Applications

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Clause 10.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Information Security Management Systems, Risk Management, ISO Review Podcast, SimplifyISO, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #SimplifyISO#Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: ISO 42001, the world's first artificial intelligence management system International standard. In this episode we discuss Clauses 8.1 - 8.4.

POINTS DISCUSSED

  1. Evolutions in Standards - How the significant changes in the ISO 9,001 standard over the years reflect the evolving needs of industries and technology.
  2. Harmonized Structure - The benefits of having ISO standards with a harmonized structure, and how does it aids companies in implementing multiple standards
  3. Operational Planning in AI - ISO 42001 for AI involves extensive operational planning and control, and presents some unique challenges in operationalizing AI systems compared to traditional systems like ISO 9001.
  4. Risk and Opportunity Management - How the inclusion of risks and opportunities in Clause 6 of ISO 42001 help in better management of AI systems
  5. AI Impact Assessment - The key factors an organization should consider when performing an AI system impact assessment.
  6. AI Risk Treatment - Potential risk treatment strategies an organization might use to mitigate AI-related risks.
  7. Auditing Procedures - How the approach towards auditing in AI differs from auditing other ISO management systems, given the unique nature of AI risks and controls?
  8. Cultural Adaptability - Making procedures adaptable for multicultural organizations, and how organizations can ensure their AI management systems are culturally adaptable?
  9. Trust but Verify in AI - The necessity to verify AI outputs, why its critical to verify AI results, and some effective methods to do so.
  10. Future of AI Standards - Considering the rapid advancements in AI, how future iterations of ISO 42001 might evolve to address new challenges and opportunities in the field of artificial intelligence.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Clause 9 - 10.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn how to becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: ISO 42001, the world's first artificial intelligence management system International standard. In this episode we discuss Clauses 4-7.

POINTS DISCUSSED

  1. AI's Rapid Advancement and Implications for businesses.
  2. Importance of AI Standards and their value even if companies don't seek certification.
  3. ISO Standard Details, introduction to the standard structure, and what to expect in the Clauses.
  4. Overview of Clauses 1, 2, and 3
  5. Clause 4 - 7 Context
  6. Leadership and Commitment: Leadership Responsibilities; Commitment to the AI management system; Resource Allocation; Ensuring communication and importance; Integration of System Requirements; Alignment with business processes: AI Policies; Framework for setting objectives; Organizational Structure; and Ownership and protection of AI assets.
  7. Risk Management and Procedures: Development and Integration; Risk assessment and treatment; "Plan, Do, Check, Act" Cycle; Managing and mitigating risks; Framework for Risk Assessment; Consistent and reliable guidelines; Documentation and Audit Processes; and Evaluating risk treatment effectiveness.
  8. Annex A and Implementation Guidelines

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Clause 8.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox, Podcast Interview

ISO42001 #ArtificalIntelligence #AI #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast #Podcast Interview

View Details

Howard and Jim chat about an exciting new frontier: the emergence of ISO 42001, the world's first artificial intelligence management system International standard.

POINTS DISCUSSED

  1. How ISO/IEC 42001:2023 compares to other existing Harmonized Structure ISO standards like ISO 9001, ISO 27001 and ISO 14001 in terms of structure.
  2. The ways in which ISO 42001 standard addresses ethical considerations in the use of artificial intelligence.
  3. The role of transparency and continuous learning as outlined in the ISO 42001 standard, and how these elements contribute to responsible AI use.
  4. Given the rapid evolution of AI technologies, how frequently should users anticipate updates to ISO/IEC 42001:2023?
  5. Practical examples of how the automotive industry is utilizing AI to enhance part design and reduce time-to-market.
  6. How organizations that choose not to pursue formal ISO certification can still benefit from implementing the practices outlined in ISO 42001.
  7. The key risk assessment strategies detailed in the ISO 42001 standard, and why are they crucial for organizations implementing AI.
  8. How ISO 42001 facilitates compliance with legal and regulatory requirements surrounding the use of AI technologies.
  9. The inclusion of over 50 countries in Technical Committee 42 and supporting working groups, as well as public feedback. These contributors add to the robustness and applicability of the standard.
  10. The advantages of integrating ISO 42001 with other existing ISO standards to build a comprehensive management system framework.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard, Clauses 4 -10.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

KEYWORDS

ISO 42001, Artifical Intelligence, AI, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO42001 #ArtificalIntelligence #AI #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Clause 8.3 - Conduction Reviews and Clause 8.4 - Analysis and Reporting Results.

POINTS DISCUSSED

  1. The key components of clauses 8.3 and 8.4 of ISO 27008, and why are they critical for conclusions about the effectiveness of your information security management system.
  2. The importance of why auditors should remain unbiased and provide factual reports, and maintain objectivity and reliability during the review process.
  3. Why assessing and gathering evidence during the control review process is essential, and the methods or tools that could be employed to enhance the effectiveness of this evidence collection.
  4. How organizations can identify non-conformances in their information security management systems and turn these into opportunities for improvement.
  5. Why is it essential to assess potential compromises to confidentiality, integrity, and availability, and the strategies that can be implemented to strengthen these areas.
  6. The necessity for auditors to be skilled in both information security and communication, and the training or development initiatives that would help auditors enhance these skill sets.
  7. How can top management foster a culture of information security awareness within their organizations.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimchat about the ISO/IEC 42001 AI management system standard.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO 27001, Clause 8.3: Conduction Reviews, Clause 8.4: Analysis and Reporting Results, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #InformationSecurityManagementSystems #RiskManagement #Control Assessment Process, #ISOReviewPodcast.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019, Clause 8.2.9: Extended Review Procedures, 8.2.10: Optimization, and 8.2.11: Finalization.

POINTS DISCUSSED

  1. Information Assets and Organization
  2. Extended Review Procedures
  3. Optimization Strategies
  4. Case Study Reflection
  5. Internal Auditing
  6. Organization-Specific Conditions
  7. Workflow Auditing
  8. Impact of Unexpected Events
  9. Preparations for Conducting Interviews
  10. Anticipating AI in ISO Standards

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Clause 8.3 and Clause 8.4.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO 27001, Clause 8.2.9 Extended Review Procedures, 8.2.10 Optimization, and 8.2.11 Finalizationn, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #InformationSecurityManagementSystems #RiskManagement #Control Assessment Process, #ISOReviewPodcast.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Clauses 8.2.6 - Work Assignments, 8.2.7 - External Systems, and 8.2.8 - Information Assets and Organization.POINTS DISCUSSED

  1. The importance of thinking about information as an asset, and how can this mindset shift impact the effectiveness of an organization's information security management system .
  2. The inevitability of cyberattacks, and how ISO 27001 prepares organizations for the inevitable rather than the hypothetical.
  3. The significance of auditor independence and objectivity in the context of information security assessments, and how can organizations ensure these principles are upheld?.
  4. The challenges of auditing external systems, particularly those in the cloud, and the strategies organizations employ to mitigate these challenges?
  5. How the guidelines help organizations create more robust contracts with their suppliers and service providers.
  6. Daily practices, akin to a pilot's pre-flight checklist, for maintaining information security awareness within an organization.
  7. The role of incident response plans in mitigating the impact of cyberattacks, and how can organizations ensure these plans are effective and well-practiced.
  8. The importance of using standards-based testing protocols in assessments.
  9. How the concept of layered process auditing (LPA) improves the continuous monitoring and enhancement of an ISMS.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Clause 8.2.9 - Extended Review Procedures, Clause 8.2.10 - Optimization, and Clause 8.2.11- Finalization.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO 27001, Clause 8.2.6 - Work Assignments, Clause 8.2.7 - External Systems, and Clause 8.2.8 - Information Assets and Organization, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #InformationSecurityManagementSystems #RiskManagement #Control Assessment Process, #ISOReviewPodcast.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Clause 8.2.4 - Object-Related Procedures, and 8.2.5 - Previous FindingsPOINTS DISCUSSED

  1. How has the role of information security management systems evolved over time, and what key changes have occurred in the past few years?
  2. What are some specific methods organizations can use to review their information assets, and how do these methods ensure the verification of controls?
  3. How can an organization measure the effectiveness of its information security controls, and what steps should be taken if a control is found ineffective?
  4. Why is it necessary to review previous findings during an information security assessment, and how can this practice improve the overall security posture of an organization?
  5. How do changing conditions and emerging technologies impact information security assessments, and what measures can organizations take to keep their assessments relevant?
  6. In what scenarios might an organization benefit from using multiple review methods for assessing information assets, and how can these methods complement each other?
  7. What skills and knowledge are essential for information security auditors, and how can they stay updated on the latest developments in the field?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Clause 8.2.6: Work Assignments; Clause 8.2.7: External Systems, Clause 8.2.8: Information Assets and Organization; and Clause 8.2.9: Extended Review Procedure

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO 27001, Clause 8.2.4 - Object-Related Procedures, Clause 8.2.5 - Previous Findings, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #InformationSecurityManagementSystems #RiskManagement #Control Assessment Process, #ISOReviewPodcast

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Clause 8.2 - Planning the Assessment: Clauses 8.2.1, 8.2.2 and 8.2.3POINTS DISCUSSED

  1. ISO/IEC TS 27008:2019 - Clause 8.2 - Planning the Assessment clauses 8.2.1, 8.2.2 and 8.2.3.
  2. Some common misconceptions people have about ISO standards.
  3. The importance of planning when assessing controls. How the "Plan, Do, Check, Act" methodology fits into the assessment process, and why is it crucial.
  4. The risks associated with the auditing process itself, and how can auditors mitigate these risks
  5. How organizations can ensure that their controls are not just being followed but are genuinely effective in managing risks.
  6. The benefits of continuous monitoring, and can organizations implement it effectively.
  7. Reviewing procedures related to controls, and the key elements that should be reviewed to ensure these controls are functioning as intended.
  8. The importance of seeking input from the staff using the controls, and how organizations can create a culture where employees feel comfortable suggesting improvements.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Clause 8.2.4 - Object-Related Procedures, and 8.2.5 - Previous Findings,

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO 27001, Clause 8.0 Control Assessment Process, Clause 8.2 - Planning the Assessment, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #InformationSecurityManagementSystems #RiskManagement #Control Assessment Process, #ISOReviewPodcast

View Details

**Howard and Jim chat about ISO/IEC TS 27008:2019 - Clause 8.0 - Control Assessment Process: Clause 8.1 - Preparation.

POINTS DISCUSSED**

  1. Why is a thorough preparation essential for a successful ISO 27001 Annex A audit?
  2. How can management support and engagement influence the outcome of an ISO 27001 Annex A audit?
  3. What are the critical steps that organizations must complete before an ISO 27001 Annex A audit?
  4. What are the key components of an effective audit plan, and why are they important?
  5. How does communication play a role in the success of ISO 27001 audits and organizational activities?
  6. What methods do auditors use to gather evidence during an ISO 27001 Annex A audit?
  7. Why is the competence of an auditor crucial for the success of an ISO 27001 Annex A audit?
  8. How can organizations foster a culture of information security awareness among their employees?
  9. What are some common challenges organizations face when preparing for an ISO 27001 Annex A controls assessment?
  10. How can organizations use feedback from previous audits to improve their current preparation and control implementation?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Clause 8.2 - Planning the Assessment.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO 27001, Clause 8.0 Control Assessment Process, Clause 8.1 Preparation, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #InformationSecurityManagementSystems #RiskManagement #Control Assessment Process, #ISOReviewPodcast

View Details

**Howard and Jim chat about ISO/IEC TS 27008:2019 - Assessing Information Security Controls, Sampling Techniques - Clause 7.5.

POINTS DISCUSSED**

  1. Introduction and Context
  2. The importance of neutrality and objectivity in selecting sample items for an audit.
  3. The criteria used to determine samples.
  4. The steps that should be taken after an audit to ensure effective communication of results and implementation of corrective actions.
  5. The implications when auditors focus on conformance rather than looking for nonconformance, and how this perspective shift impact the outcome of an audit.

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Process for Assessing Controls, Clause 8.1.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, Sampling Techniques, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #TSamplingTechniques #ISOReviewPodcast

View Details

**Howard and Jim chat about ISO/IEC TS 27008:2019 - Assessing Information Security Controls, Testing and Validation Techniques - Clauses 7.4.4 - 7.4.7.

POINTS DISCUSSED**

  1. Introduction and Context
  2. Testing Techniques for ISO 27001 Systems - Annex A Controls
  3. The Importance of Information Security Testing
  4. Testing and Validation Techniques - Clauses 7.4.4 - 7.4.7
  5. Grey Box Testing, Double Grey Box Testing, Tandem Testing, and Reversal.
  6. Preparations an auditor make prior to conducting any form of testing on an information security management

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Sampling Techniques - Clause 7.5.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, Testing and Validation Techniques, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #TestingAndValidationTechniques #ISOReviewPodcast

View Details

**Howard and Jim chat about ISO/IEC TS 27008:2019 - Assessing Information Security Controls, Testing and Validation Techniques - Clauses 7.4.1 - 7.4.3

POINTS DISCUSSED**

  1. Introduction and Context
  2. Testing Techniques for ISO 27001 Systems
  3. Testing and Validation Techniques - Clause 7.4.
  4. The Importance of Information Security Testing
  5. Blind Testing & Double Blind Testing
  6. Preparations an auditor make prior to conducting any form of testing on an information security management

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Testing and Validation Techniques - Clauses 7.4.4 - 7.4.7.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, Testing and Validation Techniques, ISO Review Podcast, Jim Moran, Howard Fox

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #TestingAndValidationTechniques #ISOReviewPodcast

View Details

**Howard and Jim chat about ISO/IEC TS 27008:2019 - Review Methods, Overview, and Process Analysis - Clauses 7.1-7.3.

POINTS DISCUSSED**

  1. What are the key takeaways from Jim's explanation of ISO 27008 and the review methods overview and process analysis discussed in the episode?
  2. How do you think the use of flowcharts to document procedures and audit controls can benefit organizations in assessing their security controls as per ISO standards?
  3. What are some effective communication skills that an auditor should possess when reviewing controls, and why are these skills crucial for the auditing process?
  4. In the context of information security controls, what are your thoughts on the importance of testing and validation techniques in ensuring the effectiveness of controls without risking the security of the system?
  5. How can the analysis of processes and activities help organizations in managing risks and finding ways to improve their control systems as per ISO 27001?
  6. Jim mentioned the importance of reviewing mechanisms, system operations, administrative processes, and physical security measures. How can organizations ensure comprehensive assessment of these aspects while adhering to ISO standards?
  7. The episode discussed the need to obtain verifiable evidence through interviews, inspections, observations, and analysis. In your opinion, what are some effective ways to gather such evidence during an audit?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODES

Howard and Jimcontinue to deep dive into ISO/IEC TS 27008:2019 - Review Methods: General, Blind testing and Double blind testing - Clauses 7.4.1- 7.4.3.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and shares.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, ISO Review Podcast, Jim Moran

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast

Note: As an Amazon Associate, we earn from qualifying purchases.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Guidelines for the assessment of Information Security Controls - Clause 6.2 Reourcing and Competence.

POINTS DISCUSSED

  1. What are the key takeaways from the discussion on clause 6.2, resourcing and competence?
  2. How does this standard help organizations to assess the effectiveness of their information security controls?
  3. What are the skills and competencies required for information security auditors to conduct effective control assessments?
  4. How do phishing attacks and social engineering tactics put organizations at risk, and what measures can be taken to mitigate these risks?
  5. What were the main points in the discussion about the importance of thorough assessment and the need for adequate time to conduct these assessments?
  6. How do ISO standards like 27001, 27002, 27005, 27007, and 27008 contribute to the overall management of information security in an organization?
  7. What are the potential risks and benefits of engaging subject matter experts in information security auditing?
  8. How can organizations work towards continuous improvement in their information security management system through regular audits and training?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODE

Howard and Jim Deep Dive into ISO/IEC TS 27008:2019 - Review Methods, Overview and Process Analysis - Clause 7.1-7.2.

NEXT STEPS

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

Jim Moran, Simplify ISO, ISO, ISO 27008, Information Security Management Systems, Risk Management, ISO Review Podcast, Howard Fox

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast

Note: As an Amazon Associate, we earn from qualifying purchases.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Overview of Information Security Control Assessments - Clauses 6.1.4 - 6.1.5.

POINTS DISCUSSED

  1. How does the process of obtaining permission to access all areas and controls play into the effectiveness of an information security audit?
  2. Why is it crucial for auditors to create a review checklist, and what should typically be included in this checklist?
  3. In what ways do discussions with employees provide valuable insights into the efficacy of the information security management system?
  4. How do auditors provide "reasonable assurance" about the achievement of information security goals?
  5. How can organizations strike a balance between accepting a certain level of risk and ensuring adequate backup and protection to counter threats?
  6. What are some of the latest trends in risk-based approaches to information security that organizations need to stay abreast of?
  7. The importance of objective analysis and professional reporting during the audit, and what makes an auditor skilled in this aspect
  8. What are the main challenges when ensuring that all employees understand and follow the established policies and procedures?
  9. What resources and training should organizations prioritize to equip their teams for effective information security management?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODE

Howard and Jim Deep Dive into ISO/IEC TS 27008:2019 - Guidelines for the assessment of Information Security Controls - Clause 6.2, Resourcing and Competence.

NEXT STEPS

Please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, ISO Review Podcast

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast

Note: As an Amazon Associate, we earn from qualifying purchases.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Overview of Information Security Control Assessments - Clauses 6.1.1 - 6.1.3.

POINTS DISCUSSED

  1. What strategies can organizations employ to ensure that their procedures are not only being followed but are also working efficiently and effectively?
  2. How do supply chain contracts affect information security activities, and what role does software play in managing these changes?
  3. What are some of the risks involved with updates and changes in software, and how can planning and risk assessment help minimize those risks?
  4. In the development of checklists for ISO standard compliance, what elements are crucial to include for proper evidence verification and results recording?
  5. Discuss the importance of auditor preparedness, and how can an auditor prepare for assessing information security controls.
  6. How an understanding of business process interconnectivity within the supply chain enhances an auditor's ability to assess information security controls.
  7. Recommended resources for auditors and other professionals to stay informed about technical security standards and best practices.
  8. The role of third-party tests and assessments in the overall audit process, and how should companies approach integrating these findings into their information security framework?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODE

Howard and Jim Deep Dive into ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls - Clause 6, Part II.

NEXT STEPS

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Book Recommendations:
Turn the Ship Around!: A True Story of Turning Followers into Leaders by L. David Marquet

The Checklist Manifesto: How to Get Things Right by Atul Gawande

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, ISO Review Podcast

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast

Note: As an Amazon Associate, we earn from qualifying purchases.

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls - Clause 5_Background

POINTS DISCUSSED

  1. What are the key takeaways from the discussion on ISO 27008 and its significance for organizations in terms of information security controls and guidelines?
  2. How do information security controls play a vital role in managing unacceptable risks and promoting effective implementation within organizations, as outlined in the episode?
  3. What were the technical assessment aspects clarified in the episode, especially concerning the assessment of organizational controls, people controls, physical controls, and technological controls?
  4. How does the discussion emphasize the importance of maintaining and improving information security controls and the potential impact of internal and external factors on control effectiveness?
  5. In what ways can ISO 27008 and its application help organizations identify potential problems and shortfalls in control implementations, leading to improved risk mitigation and decision-making processes?
  6. How did the episode shed light on the role of audits and the necessity for objectivity in assessing the compliance and effectiveness of information security controls within the ISO 27008 framework?
  7. What are the potential benefits and implications for organizations in terms of stakeholder confidence, regulatory compliance, and management decisions, resulting from the effective implementation and assessment of information security controls?
  8. How does the episode set the stage for the upcoming discussions on clauses 6, 7, and 8, along with the various annexes?

LEARN MORE

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

UPCOMING EPISODE

Howard and Jim Deep Dive into ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls - Clause 6, Part I.

NEXT STEPS

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website, and learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn ArticlesYouTube

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27008, Information Security Management Systems, Risk Management, Artificial Intelligence, ISO Review Podcast

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #ISOReviewPodcast

View Details

Howard and Jim chat about ISO/IEC TS 27008:2019 - Guidelines for the Assessment of Information Security Controls.

Points discussed include:

  1. How do the ISO 27008 and ISO 27001 standards work together to enhance information security within organizations?
  2. Why is it important for organizations to have good monitoring systems in place, and what are some key considerations for setting up effective monitoring?
  3. What are the controls outlined in ISO 27008, and how do they contribute to improving risk management and stakeholder approval?
  4. In what ways can artificial intelligence be utilized to identify risks and enhance the monitoring of information security controls within organizations?
  5. How does the ISO 27008 standard contribute to providing assurance to stakeholders such as customers, partners, and regulatory bodies regarding an organization's robust information security management process?
  6. How can organizations effectively integrate the assessment of controls outlined in ISO 27008 with other ISO standards, such as ISO 27001 and ISO 27002?
  7. What role do people and training play in maintaining the security of information within organizations?
  8. What are some best practices for conducting internal audits to assess the effectiveness of Annex A controls, risk management, and improvement opportunities within an organization's information security management system?

Complimentary ISO Resources

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

Upcoming EpisodeHoward and Jim Deep Dive into Information Security Controls, ISO/IEC TS 27008:2019.

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords

ISO, ISO 27001, ISO 27008, Information Security Management Systems, Risk Management, Artificial Intelligence, AI, Podcast Interview

ISO27001 #ISO27008 #InformationSecurityManagementSystems #RiskManagement #ArtificialIntelligence #AI #PodcastInterview

View Details

Howard and Jim chat about "Additional Observations and Benefits of Integrating an ISO 27001 Into an Existing ISO 9001 Quality Management System."

Points discussed include:

  1. How can integrating ISO 27001 into an existing ISO 9001 system benefit an organization?
  2. What are the key differences between ISO 9001 and ISO 27001 in terms of structure and requirements?
  3. How can organizations effectively identify and assess information security risks according to ISO 27001?
  4. What role does leadership play in implementing and maintaining an effective information security management system?
  5. How can organizations ensure that all employees are fully aware of their impact on information security within the organization?
  6. What are some potential weaknesses in communication with suppliers that may pose a risk to information security?
  7. How can organizations utilize visual representations, such as flowcharts, to enhance their management systems?
  8. What are some best practices for conducting internal audits that address the requirements of ISO 27001?
  9. How does ISO 27001 emphasize the need for continual improvement in information security management?
  10. What additional controls and requirements does ISO 27001's Annex A introduce, and how can organizations effectively implement them?

Complimentary ISO Resources

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

Upcoming EpisodeHoward and Jimchat about the Guidelines for the Assessment of Information Security Controls, ISO IEC TS 27008:2019.

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Connect with Howard on LinkedIn.

Keywords#ISO #ISO27001 #ISO27001Certification #ISO27001Integration #InformationSecurityManagementSystems

View Details

Howard and Jim chat about ISO 27036-2, Clause 7.5 - Supplier Termination Process.

Points discussed include:

  1. How important is it for organizations of all sizes to prioritize information security?
  2. What are some challenges organizations face when it comes to supplier relationship termination?
  3. How can ISO standards help organizations in managing their supplier relationships and information security?
  4. What are some potential risks or consequences of not properly terminating a supplier relationship?
  5. How can organizations ensure a smooth and secure transition when terminating a supplier relationship?
  6. What role does communication play in the supplier termination process, particularly in terms of information security?
  7. What are some best practices for creating a termination plan within a supplier agreement?
  8. How can organizations protect their information and intellectual property during and after a supplier relationship termination?
  9. What steps should organizations take to ensure legal and regulatory compliance during the supplier termination process?
  10. How can organizations evaluate the effectiveness of their supplier termination process in terms of information security?

Complimentary ISO Resources

Click here to try Conformance1's free online ISO 27001 Gap Checklist.

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Connect with Howard on LinkedIn.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #SupplierRelationshipTerminationProcess

View Details

Howard and Jim chat about ISO 27036-2, Clause 7.4 - Supplier Relationship Management Process.

Points discussed include:

  1. The importance for organizations to have a process for managing supplier relationships in terms of information security.
  2. The potential risks or vulnerabilities that organizations may face when it comes to information security in the supply chain.
  3. What organizations can do to ensure that their suppliers are meeting the information security requirements stated in the contract.
  4. The role communication plays in ensuring successful supplier relationship management in terms of information security.
  5. The ways organizations can effectively monitor and enforce compliance with information security requirements in the supplier relationship.
  6. Key considerations for organizations when transitioning from one supplier to another in terms of information security.
  7. What organizations can do to mitigate the risks associated with information security during the transition to a new supplier.
  8. The steps organizations can take to train their employees on information security requirements in the supplier relationship.
  9. The potential challenges or obstacles that organizations may face when managing supplier relationships in terms of information security.
  10. What steps can organizations prepare for and respond to situations where information security issues arise in the supplier relationship?

Complimentary ISO Resources

Click here to try Conformance 1's free online ISO 27001 Gap Checklist.

Upcoming EpisodesHoward and Jimchat about:

  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.5 - Supplier Relationship Termination Process

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #SupplierRelationshipAgreement

View Details

Howard and Jim chat about ISO 27036-2, Clause 7.3 - Supplier Relationship Agreement Process.

Points discussed include:

  1. How important it is for businesses to have supplier contracts that address information security?
  2. The key elements that should be included in an agreement to ensure information security.
  3. How can businesses effectively measure their suppliers' compliance with information security requirements?
  4. What role does change management play in supplier agreements and information security?
  5. How can businesses ensure a smooth transition with their suppliers when it comes to information security?
  6. The potential risks and challenges businesses face when it comes to maintaining information security in the supply chain.
  7. How businesses can effectively monitor and enforce their suppliers' compliance with information security standards.
  8. The criteria businesses should use when selecting suppliers for information security purposes.
  9. The measures businesses can take to protect sensitive information during and after the termination of a supplier agreement.
  10. Industry-specific considerations or regulations that businesses should be aware of when it comes to information security in the supply chain

Complimentary ISO Resources

Click here to try Conformance 1's free online ISO 27001 Gap Checklist.

Upcoming EpisodesHoward and Jimchat about:

  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.4 - Supplier Relationship Management Process
  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.5 - Supplier Relationship Termination Process

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #SupplierRelationshipAgreement

View Details

Howard and Jim chat about ISO 27036-2, Clause 7.2 - Supplier Selection Process.

Points discussed include:

  1. How can organizations effectively plan their supplier relationships to mitigate information security risks?
  2. What are some real-life examples of information security breaches and their impact on organizations?
  3. Why is it important for organizations to communicate the importance of information security to all employees, and how can top management lead by example?
  4. What are some key elements that should be included in a supplier relationship plan to ensure information security?
  5. How can organizations assess and manage risks in their relationships with suppliers?
  6. Why is it impossible to eliminate all information security risks, and how can organizations determine acceptable levels of risk?
  7. What role does legal and regulatory compliance play in supplier relationship planning for information security?
  8. How can organizations ensure that their suppliers are complying with information security requirements and addressing potential risks?
  9. What are some considerations for evaluating new suppliers in terms of their information security impact?
  10. Why is it important to continually maintain and update information security measures in an organization?

Complimentary ISO Resources

Click here to try the online ISO 27001 Gap Checklist.

Upcoming EpisodesHoward and Jimchat about:

  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.3 - Supplier Relationship Agreement
  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.4 - Supplier Relationship Management Process
  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.5 - Supplier Relationship Termination Process

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #I

View Details

Howard and Jim chat about ISO 27036-2, - Clause 7.1 - Supplier Relationship Planning Process.

Points discussed include:

  1. How do the ISO 27036 standards help protect against potential risks and ensure personal safety?
  2. What are some potential legal and regulatory issues that suppliers should be aware of in relation to information security impacts?
  3. Why is it important for requirements and agreements with suppliers to be strongly worded and clearly labeled as "shall"?
  4. What are real-life examples where a breach in information security had devastating effects on a company's asset value or credibility?
  5. What are some challenges in protecting against breaches and maintaining information security measures in organizations?
  6. What steps should companies take to address information security concerns proactively, rather than waiting for clients to request it?
  7. What are some key steps individuals can take to maintain cybersecurity in their supply chain?

Complimentary ISO Resources

Click here to obtain your copy of the ISO 27001 Gap Checklist.

Upcoming EpisodesHoward and Jimchat about:

  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.2 - Supplier Selection Process
  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.3 - Supplier Relationship Agreement
  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.4 - Supplier Relationship Management Process
  • ISO 27036-2 Supplier Relationship Requirements - Clause 7.5 - Supplier Relationship Termination Process

Next StepsIf you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #ISO27036

View Details

Howard and Jim chat about ISO 27036 Part 2 - Clause 6 - Information security in supplier relationship management

Points discussed include:

  1. How does the ISO Review podcast contribute to the understanding and implementation of ISO standards in various industries?
  2. What are some practical steps that companies can take to ensure information security in supplier relationships?
  3. How has the globalized supply chain impacted the security of information and data?
  4. Why is it important for businesses to prioritize quality assurance processes and follow Mr. Deming's principles?
  5. In what ways can hardware and software work together to enhance information security and ensure smooth operations?
  6. How can businesses effectively assess and manage the risks associated with information security in the supply chain?
  7. What role does project management play in the acquisition process and information security management?
  8. How do the principles outlined in ISO 27036 part two align with the practice of continuous improvement in business processes?
  9. What are some common challenges and pitfalls that companies face when implementing information security measures in supplier relationships?
  10. What resources or tools are available to businesses that want to learn more and improve their understanding of ISO standards and information security practices?

On Our Next EpisodesHoward and Jimchat about ISO 27036 Part 2 - Clause 7 - Information security in a supplier relationship example

Next Steps
If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Click here to learn more about the ISO 27001 Gap Checklist.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #AnnexA #RiskAssessment

View Details

Howard and Jim chat about ISO 27036 Part I - Protecting Your Data: Overview of Understanding the Risks and Best Practices Guidance for Supplier Relationships.

Points discussed include:

  1. Why is due diligence important when choosing suppliers?
  2. Why it's important to evaluate the security practices and capabilities of suppliers to make sure that they meet your information security requirements.
  3. What are the key factors to consider when evaluating supplier relationships for information security practices and capabilities?
  4. Why you need to have processes to manage the information security risks with interacting with your suppliers.
  5. Why you need to create a culture of information awareness, make sure every day, every single person in your in your organization is thinking information security all day long!

On Our Next EpisodesHoward and Jimchat about ISO 27036-2 - Requirements for Information Security in your Supplier Relationships.

Next Steps
If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Click here to learn more about the ISO 27001 Gap Checklist.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #AnnexA #RiskAssessment #ISOHarmonizedStructure #StatementofApplicability #InternationalStandardsDevelopmen #SimplifyISO #ISO27001:2022 #ISO27008

View Details

Howard and Jim chat about ISO 27008 Guidelines for Assessing Annex A Controls.

Points discussed include:

  1. How many controls are required in ISO 27,008?
  2. What are the seven steps outlined in ISO 27,008 for measuring and assessing controls?
  3. How can ISO 27,008 help organizations improve information security?
  4. What is the significance of continual improvement in information security controls?
  5. What will be the focus of the next episode of the ISO Review Podcast?

On Our Next EpisodesHoward and Jimchat about ISO 27036-1 Overview & Concepts and ISO 27036-2 Supplier Relationships’ Requirements.

Next Steps
If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #InformationSecurityManagementSystems #AnnexA #RiskAssessment #ISOHarmonizedStructure #StatementofApplicability #InternationalStandardsDevelopmen #SimplifyISO #ISO27001:2022 #ISO27008

View Details

Howard and Jim chat about Competence Requirements For Information Security Management Systems Professionals.

Points discussed include:

  1. What is the importance of communication and documentation in auditing firms for ISMS professionals?
  2. How can auditors prepare for an audit, and what information should they request from the organizations being audited?
  3. What ethics are involved in auditing and what is the importance of ethics in firms and individuals who perform tasks in companies?
  4. What are some qualifications that ISM professionals need to have in order to become auditors?
  5. What are some key attributes and skills that auditors need to have in order to perform their job responsively and ethically?
  6. What are some of the challenges that auditors may face in conducting an objective and fair audit, and how can they overcome these challenges?
  7. Where can listeners go to learn more about ISO auditing and the topics discussed in this podcast episode?

On Our Next EpisodeHoward and Jimchat about ISO 27008 Guidelines for Auditing Annex A Controls.

Next Steps
If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedInLinkedIn Articles:YouTubeLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

Keywords#ISO #ISO27001 #ISO27001Certification #Registrars #ITProjects #InformationSecurityManagementSystems #AnnexA #RiskAssessment #ISOHarmonizedStructure #StatementofApplicability #InternationalStandardsDevelopmen #SimplifyISO #ISO27001:2022 #AnnexA

View Details

Howard and Jim chat about the Path to ISO 27001 Certification.

Points discussed include:

  1. What is ISO 27001 and why do some organizations need certification in it?
  2. Do most organizations need to be certified in ISO 27001 to bid on projects in the future?
  3. What is the process for achieving ISO 27001 certification?
  4. Why is formalizing and structuring information management important for organizations?
  5. What are the risks if an organizations buys pre-created or pre-crafted procedures or documentation for ISO 27001 certification?
  6. What are the ISO 27001 certification path scenarios where an organization has no ISO certification and a scenario where an organization is certified to another ISO standard for achieving ISO 27001 certification?
  7. How long does it take to complete the statement of applicability for an ISO 27001 system?
  8. Is there help available for organizations to implement ISO 27001?
  9. Competence Requirements for Information Security Management Systems Professionals.

Next Steps
If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Clieck here to learn more about the ISO 27001 Gap Checklist.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/ LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/ YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8gLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

ISO #ISO27001 #ISO27001Certification #Registrars #ITProjects #InformationSecurityManagementSystems #AnnexA #RiskAssessment #ISOHarmonizedStructure #StatementofApplicability #InternationalStandardsDevelopmen #SimplifyISO #ISO27001:2022 #AnnexA

View Details

Howard and Jim chat about ISO 27001, Annex A - Technical Controls.

Points discussed include a review of the 14 controls in Clause 8:

  • Annex A, Clause Eight, Technical Controls
  • Number of controls:14 (8.1 to 8.34)

On Our Next EpisodeThe Path to ISO 27001 Certification.

Next Steps - review your current situation against these controls to see if you can find a way to improve your Technical Controls for better Information security.

If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/ LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/ YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8gLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about ISO 27001, Annex A - Physical Controls.

Points discussed include a review of the 14 controls in Clause 7:

  • Annex A, Clause Seven, Physical Controls
  • Number of controls:14 (7.1 to 7.14)

On Our Next EpisodeISO 27001, Annex A - Clause 8 - Technology Controls.

Next Steps - review your current situation against these controls to see if you can find a way to improve your Pyysical Controls for better Information security.

If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/ LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/ YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8gLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about ISO 27001, Annex A - People Controls.

Points discussed include a review of the 8 controls in Clause 6:

  • Annex A, Clause Six, People Controls
  • Number of controls: 8 (6.1 to 6.8)

On Our Next EpisodeISO 27001, Annex A - Clause 6 - Physical Controls.

Next Steps - review your current practices against these controls required to see if you can find a way to improve your Organizational controls for better Information security.

If you enjoyed this episode, please follow us on your preferredpodcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professional.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/ LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/ YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8gLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about ISO 27001, Annex A - Organization Controls.

Points discussed include a review of the 37 controls in Clause 5:

  • Annex A, Clause Five, Organizational Controls
  • Number of controls: 37 (5.1 to 5.37)

On Our Next EpisodeISO 27001, Annex A - Clause 6 - People Controls.

Next Steps - review your current practices against these controls required to see if you can find a way to improve your Organizational controls for better Information security.

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Click here to visit the International Management System Institute website so that you can learn about how and why you should consider becoming a Certified ISO Management System Professionalm.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/ LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/ YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8gLearn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about Root Cause Analysis Considerations For Your ISO 27001 Information Security Management System.

Points discussed include:

  • Root Cause Analysis Considerations
  • Determine the Cause of the Nonconformance
  • Contributing Issues
  • Ishikawa Fishbone Diagram Integration With Annex A
  • 4-Column Integration Table showing the Ishikawa Fishbone and the 4 Annex A Clauses (See Link)

Our Gift To You4-Column Integration Table showing the Ishikawa Fishbone and the 4 Annex A Clauses
On Our Next EpisodeUsing ISO 27001 with ISO 22301 to Maintain Business Continuity

Next Steps

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about the integration of an ISO 27001 into an existing ISO 9001 QMS.

Points discussed include:

  • ISO 9001 Quality Management Standard is the most prevalent in the world. It's been around since 1987 and there are over 2 million certificates worldwide in over 170 countries.
  • Best Practice would be to integrate ISO 27001 into your existing ISO 9001 system (or any other Harmonized Standard system) instead of having two separate systems.
  • Start off by reviewing Clause 4 and make any necessary tweaks such as the 'Interested Party' section.
  • Follow up by reviewing the other clauses , 5 though 10, to determine the sections that may need some additional IS related information.
  • Whatever method you're using to determine risks in quality, you can definitely start with that for information security risks.
  • Create your Statement of Applicability from Annex A.

On Our Next Episode

In the next episode of the ISO Review Podcast, Jim will discuss Root Cause Analysis Considerations for your ISO 27001 Information Security Management System

Next Steps

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about the ISO 27001:2022 - Statement of Applicability (SoA)

Items discussed include:

  • The Statement of Applicability is required for ISO 27001 certification. It’s a statement that explains which Annex A security controls are — or aren’t — applicable to your organization’s Information Security Management System (ISMS).

You can update your current ISO 27001 Statement of Applicability (SoA) like this:

  • Compare your current SoA to the new requirements - there are charts in the new Standard showing the connections
  • Identify the business owners in the various risk areas, and assign a high-medium-low value to the risk, and then revise your Information Security Risk Treatment Plans
  • Update your Risk Treatment Plans to keep you protected
  • Keep your Risk Treatment Plans dynamic - threats never sleep!

On Our Next Episode

In the next episode of the ISO Review Podcast, Jim will discuss what you need to know about integrating ISO 27001 into an existing ISO 9001 QMS.

Next Steps

If you enjoyed this episode, please follow us on your preferred podcast directory. We appreciate your likes & comments, and invite you to share episode with anyone who might benefit from learning about this topic.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about ISO 27007 - Guidance for Information Security Management Systems Auditing.

Items discussed include:

  • Plan - Do - Check - Act Approach.
  • Getting clients to ask their auditees if the procedure, the way it's been implemented, is getting them the results they want.
  • The purpose of auditing is to see if you're getting the results you want.
  • Part of the audit is to see if the objectives are really sensible.
  • Asking during the audit if there's any possible way the auditees think that procedures, processes, and the implementation could be improved.
  • The reocmmended frequency for performing audits.
  • Review the competency of the individuals and teams assigned to perform the audit.

During the next episode of the ISO review Podcast, we'll discuss the Statement of Applicability document.

Next Steps

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

Learn more about HowardClick here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jim chat about ISO 27005 - Managing Information Security Risks in this episode of the ISO Review Podcast.

Items discussed include:

  • Plan - Do - Check - Act Approach
  • Identify the risk
  • Analyze the naure and level of the risk
  • Evaluate (low - medium - high ) the risk
  • Select objectives and controls for the treatment of the risk
  • Determine what is an acceptable level of the residual risk

We look forward to having you join us next year for more episodes of the ISO review Podcast.

Next Steps

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

Learn more about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

Learn more about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

The ISO Review Podcast is a production of SimplifyISO.

View Details

Howard and Jimreview ISO 27002 - Security Techniques in this episode of the ISO Review Podcast.

Items discussed include:

Information security, cybersecurity and privacy protection — Information security controls

  1. Scope
  2. Normative References
  3. Terms, definitions, and abbreviated terms
  4. Structure of the Document
  5. Organizational controls (37)
  6. People controls (8)
  7. Physical controls (14)
  8. Technological controls (34)
  9. Annex A
  10. Annex B

The entire document has useful help in it. It's has help that's going to give users and listeners a chance to really improve their the effectiveness of their management system. It's going to help improve their outputs, their risk management and the way people can access their own Information Management System safely.

What's in Store For The Next Episode

Our topic is ISO 27005 - Managing Information Security Risks.

Next StepsClick here to visit the SimplifyISO website to discover how this cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that need to be met.

More about Jim Moran

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

The ISO Review Podcast is a production of the International Management System Institute.

The ISO Review Podcast is a production of SimplifyISO.

View Details

In this episode, Howard and Jimreview the changes in ISO 27001:2022, Information Security Management Systems Requirements

Items discussed include:

  • ISO 27001 - Information Security Management System was the pioneer in what was first known as the High Level Structure, is now called the Harmonized Structure, as it was developed for all the other standards to be built on.
  • The breadth of changes in the Clauses:
    • 4.2 - Interested Parties (minor tweak);
    • 4.4 - Description of the Entire System (additional information added);
    • 6.1 - Risk Management (additional information and clarification);
    • 6.2 - Information Security Objectives (additional information and clarification);
    • 6.3 - Change Management (new clause);
    • 7.4 - Communication (minor tweak);
    • 8.1 - Operation Planning (rewritten);
    • 9.1 - Monitoring (additional information);
    • 9.2 - Internal Auditing (expanded with new information);
    • 9.3 - Management Review - (expanded)
  • Annex A - Controls. They have been reorganized from 14 categories to 4 categories and have been reduced from 114 controls to 93:
    • Clause 5 - Organization Controls (37)
    • Clause _ - People Controls (8)
    • Clause _ - Physical Controls (14)
    • Clause _ - Technological Controls (34)
  • ISO 27002, the guidance document for Annex A (more in the next episode!)
  • The benefit of beginning recertification sooner rather than later

What's in Store For The Next Episode

  • Our topic is ISO 27002:2022 - Security Techniques, the newly updated guidance document for ISO 27001:2022 Annex A
  • Next StepsClick here to visit the SimplifyISO website to discover how this cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that need to be met.

More about Jim Moran

  • LinkedIn: https://www.linkedin.com/in/simplifyiso/
  • LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/
  • YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard

  • Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.
  • LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

The ISO Review Podcast is a production of the International Management System Institute.

View Details

Welcome to the ISO Review Podcast

In this episode, Howard and Jim discuss, Guidance for Improving your Internal Audits for an Information Security Management System.

Highlights include:

  • Does the information security auditor have the proper security clearance to access documented information.
  • Person Identifiable Information, or other sensitive information, must be handled properly according to any legal requirements that the organization might have.
  • Companies that outsource their internal audit activities, need to ensure that the outsourced auditor needs to be vetted to make sure they can view a sensitive information.
  • The lead auditor needs to determine the extent to which evidence that's not available to the audit team during the audit, affects the confidence in the audit findings.
  • The auditor needs to verify that any documentation required by the audit criteria is going to be available, and that controls have been put in place by the organization that they're auditing.
  • The introduction of Annex A and the Statement of Applicability (SOA) as described in ISO 27002:2022.

In The Next Episode

Howard & Jim will review the changes in the new edition of ISO 27001:2022

Next Steps

Click here to discover more information about the International Management System Institute on our website and to sign up for our newsletter.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

The ISO Review Podcast is a production of the International Management System Institute.

View Details

Welcome to the ISO Review Podcast

Hello, I’m Howard Fox, Business Coach and Host of the Success InSight Podcast. I am joined by Jim Moran, ISO Management System Professional, now celebrating his 30th year delivering ISO support.

In this episode, Howard and Jim discuss What You Need To Know to Become a Certified ISO Management System Professional.

Items discussed include:

  • MSP Course #1 – ISO 9004:2018 – Sustainable Success
  • MSP Course #2 – ISO 10004:2018 – Customer Satisfaction
  • MSP Course #3 – ISO 31000:2018 – Risk Management
  • MSP Course #4 – ISO 45003 – Psychosocial Health and Safety at Work
  • MSP Course #5 – ISO 56002:2014 - Innovation Management
  • MSP Course #6 – ISO 22301:2019 - Business Continuity
  • Pass a quiz for each course and complete a project that demonstrates implementation of the ISO Standard that you have completed

In The Next Episode

Howard & Jim will discuss Guidance for Improving your Internal Audits for an Information Security Management System

Next Steps

Click here to discover more information about the International Management System Institute on our website and to sign up for our newsletter.

Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, and any other ISO requirements that you have to meet.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard

Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

View Details

Welcome to the ISO Review Podcast

In this episode, Howard and Jim discuss the path to become a Certified Lead Auditor.

Points Covered

  • How to become a Certified Lead Auditor.
  • Who is the body that certifies lead auditors.
  • What are the courses that need to be taken.
  • What experience does a prospective auditor need to have.

Idea for Our Next Episodes

  • What You Need To Know to Become a Management System Professional

Next Steps

Click here to learn more about Exemplar Global.

Click here to discover more information about the International Management System Institute on our website and to sign up for our newsletter.Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, any any other ISO requirements that you have to meet.

Click here to learn more about Management System Implementation Training Courses available at The Learning Alliance.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard
Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

View Details

Welcome to the ISO Review Podcast

In this episode, Howard and Jim continue their conversation about ISO 27001, Information Security Management System (ISMS) to Manage Cyber Attacks, and unpack what specific guidance is available on how to perform an internal audit.

Highlights
Jim talks about the creation of the ISO 27007, Information Security, Cyber Security, and Privacy Protection, released in 2020, which provide guidelines for information security management systems auditing.

Audit Takeaways

  1. Are we getting the results we want?
  2. Are we managing risks related to this activity?
  3. Is there anything the auditee can think of that would help make their life better relative to the safety we want to have around information security?

Future Episode Idea

  • How to become a Certified Lead Auditor.
  • Who is the body that certifies lead auditors.
  • What are the courses that need to be taken.
  • What experience does a prospective auditor need to have.

Next Steps

Click here to discover more information about the International Management System Institute on our website and to sign up for our newsletter.Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, any any other ISO requirements that you have to meet.

Click here to learn more about Management System Implementation Training Courses available at The Learning Alliance.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard
Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

View Details

Welcome to the ISO Review Podcast

In this episode, Howard and Jim continue their conversation about ISO 27001, Information Security Management System (ISMS) to Manage Cyber Attacks, and unpack what an effective ‘implementation Plan’ looks like.

In our next and final episode of the series, we'll discuss whatSpecific Guidance is available about your ISMS.

Highlights
Jim referenced The PDSA Cycle (Plan-Do-Study-Act), developed by Dr. W. Edwards Deming. considered by many to be the master of continual improvement of quality. The PDSA is a systematic process for gaining valuable learning and knowledge for the continual improvement of a product, process, or service.

Link: https://deming.org/explore/pdsa/

Next Steps

Click here to discover more information about the International Management System Institute on our website and to sign up for our newsletter.Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, any any other ISO requirements that you have to meet.

Click here to learn more about Management System Implementation Training Courses available at The Learning Alliance.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard
Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

View Details

Welcome to the ISO Review Podcast

In this episode, Howard and Jim continue their conversation about ISO 27001, Information Security Management System (ISMS) to Manage Cyber Attacks, and unpack the benefits of implementing an ISMS.

In our next epsiode, we'll discuss whatan effective ‘implementation Plan’ looks like, follwed by the Specific Guidnace that is available to about your ISMS.

In The Media
Jim made the connection between ISO 27001 and an outage on Friday, July 8, at Rogers, one of Canada’s largest telecommunications companies, which caused significant internet, cable and cellphone disruptions, mostly in Ontario and Quebec, the country’s most populous provinces. Link to article: https://www.insurancejournal.com/news/international/2022/07/11/675306.htm

UPCOMING EVENT
Click here to register and attend a webinar hosted by The British Standards Institution (BSI),
How to use ISO 27001 to manage cyber attacks.
Date: Thursday, July 28, 2022;
Time: 2:00PM - 3:00PM ET.

Click here to discover more information about the International Management System Institute on our website and to sign up for our newsletter.Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, any any other ISO requirements that you have to meet.

Click here to learn more about Management System Implementation Training Courses available at The Learning Alliance.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard
Click here to learn more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

View Details

Welcome to the ISO Review Podcast

In this episode, Howard and Jim chat about How to Use ISO 27001 to Manage Cyber Attacks. Points that will be covered during this episode and then discussed further in subsequent episodes, include:

  • What does an ISMS look like?
  • What are the benefits of an ISMS?
  • What does an effective ‘implementation Plan’ look like? and
  • What Specific Guidance is available?

An Information Security Management System is the framework that helps organizations prepare for a cyber-attack through a process of threat assessment, monitoring and continual improvement.

A well-designed system requires that you identify potential sources of a security breach, mitigate them and provide a strong ongoing defense system for your information. An attack will happen – it’s not a case of ‘if’ it’s a matter of ‘when’.

It’s virtually impossible to predict every risk to your information and mitigate it. It is possible, however, to create and manage a system that will give you a fighting chance.

The key is preparation, detecting vulnerabilities and creating a more resilient management system, in terms of interactions with so many layers of cyber connections. That’s where an information security management systems (ISMS) fits into your future.

Deeper awareness about what does an ISMS looks like?

  • The harmonized structure of ISO 27001 integrates perfectly with other Harmonized Standards
  • Annex A requirements, if properly implemented, help keep your information assets safe
  • Audits (Internal and External) help you find ways to improve the effectiveness of your system to keep information secure

UPCOMING EVENT
Click here to register and attend a webinar hosted by The British Standards Institution (BSI),
How to use ISO 27001 to manage cyber attacks.
Date: Thursday July 28, 2022;
Time: 2:00PM - 3:00PM ET.

Click here to discover more information about the International Management System Institute on our website, and to sign up for our newsletter.Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, any any other ISO requirements that you have to meet.

Click here to learn more about Management System Implementation Training Courses available at The Learning Alliance.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard
Click here to learning more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/

View Details

The ISO Review Podcast is a production of the International Management System Institute.

The ISO Review Podcast shares the latest International Standards Development, and is your resource for getting the most out of your management systems.

The Podcast is hosted by Howard Fox, Business Coach, and Host of the Success InSsight Podcast. He is joined by Jim Moran, ISO Management System Professional, celebrating his 30th year delivering ISO support.

Twice-monthly, Jim & Howard will be sharing article highlights from the IMSI Newsletter. In this episode, Jim covers these highlights:

  • ISO Certification and Risk Management Practices
  • PFMEA: Learn How to Remove Error From a System With This 10 Step Guide
  • Bridging the Gap Between Management and Strategy
  • What is Kaizen? A Mindful System of Quality Improvement

Jim's Recommended Readings
The Black Swan: The Impact of the Highly Improbable (2nd Ed.)by Nassim Nicholas Taleb (Author) May 11, 2010.

Click here to discover more information about the International Management System Institute on our website, and to sign up for our newsletter.Click here to visit the SimplifyISO website to discover how our cloud-based management system will satisfy all the Standards requirements, client requirements, any any other ISO requirements that you have to meet.

More about Jim on LinkedIn & YouTube

LinkedIn: https://www.linkedin.com/in/simplifyiso/

LinkedIn Articles: https://www.linkedin.com/in/simplifyiso/detail/recent-activity/posts/

YouTube: https://www.youtube.com/channel/UCrt2Hgj-5AjHKEvyf2ssZ8g

More about Howard
Click here to learning more about the Coaching and Podcast Services provided by Fox Coaching, inc.

LinkedIn: https://www.linkedin.com/in/foxcoachinginc/