ISO 27001
Implementing, auditing and maintaining ISO/IEC 27001:2022, plus the ISO 27017 and 27018 cloud extensions.
Every article is filed under the framework or discipline it helps with.
Implementing, auditing and maintaining ISO/IEC 27001:2022, plus the ISO 27017 and 27018 cloud extensions.
Trust Services Criteria, report types, bridge letters, subservice organisations and running a SOC 2 programme.
ISO/IEC 42001, AI impact assessment and the EU AI Act, for teams building or deploying AI.
GDPR, ISO 27701 and how privacy laws compare on rights, records and evidence.
The DPDP Act and Rules, SEBI CSCRF, RBI cyber security directions and CERT-In requirements.
DORA, NIS2 and the Cyber Resilience Act: what applies, to whom, and what supervisors now test.
NCA ECC, SAMA CSF, UAE IAS and the Saudi and UAE data protection laws.
NIST CSF 2.0, NIST SP 800-53, CIS Controls and CMMC, from profiles to control baselines.
PCI DSS v4.0.1 requirements, SAQs and the evidence assessors ask for.
HIPAA Security and Privacy Rules and HITRUST CSF assessments.
ISO 22301, business impact analysis, exercises and operational resilience.
ISO 9001, 14001, 45001, 20000-1 and 37001, and auditing them together.
The auditor's side: sampling, writing findings, remote audits and certification body impartiality.
Collecting, naming, retaining and defending audit evidence across frameworks.
Risk appetite, compensating controls, root cause analysis and closing findings.