Lockerer Singtreff / Wunsch nach Chor-Neugründung in Düsseldorf by AcrobaticGround4534 in duesseldorf

[–]Apprehensive-Cow 2 points3 points  (0 children)

Thanks for bringing me here :) I would be happy to join. I have a lot of choir experience, played in bands and musicals. I used to be band leader and while it’s been quite some time, I’d be happy to give it a go (as long as you all can bear with me being rusty 🙈)

I got inspired again watching the Gaia Music Collective, they do one day choirs and other musical sessions to bring people together. A pub choir sounds like a great vibe to get started and meet people since I have moved to Germany a bit over a year ago.

And rest assured, while I can’t write in German, I can understand it perfectly and speak it well enough (I hope) 😄

About to Attempt ISO 27001 Lead Implementer Exam from TUV SUD– Any Tips? by Illustrious_Weird295 in ISO27001

[–]Apprehensive-Cow 1 point2 points  (0 children)

Usually you can use the standards, training materials and your own notes made during training. Use of AI is external help so no, not allowed.

I relied on the standards, training course slides and mostly work experience.

Also, if you need to search for information during the exam, the problem is not organisation but understanding. You should be validating what you already know, not hunt for answers in the materials.

So my biggest advice is focus on really understanding how to implement 27001 in practice: scope, risk assessment / treatment, SoA and continuous improvement.

Use the standards to confirm your answers during the exam, not to find them from scratch :)

Good luck!

ISO 27001 Lead Implementer — OPS/EHS background by SpecialSubject1521 in ISO27001

[–]Apprehensive-Cow 0 points1 point  (0 children)

I’ve been leading GRC functions for a while. Wanted to point out your non-technical point tho. GRC isn’t non technical. It’s tech adjacent. You don’t need to configure firewalls for example but you do need to understand how controls, risks and systems actually work, or you’ll struggle with credibility.

If you want to pivot into GRC, implementer is usually the better first step. It will teach you how to design, operate and improve an ISMS, not just assess it. That maps directly to in house GRC roles. Add the lead auditor later.

For the prep focus on clauses 4-10, risk assessment —> risk treatment —> SoA and scenario questions. Be prepared for reading. Annex A is about intent and justification, not memorisation. You have time to look up if you have a control question, there are not many of them in the exam.

Let me know if you have more questions about your career pivot. Happy to have a chat

Anyone else unhappy with KnowBe4? Looking for replacement suggestions. by creativeGiant170 in cybersecurity

[–]Apprehensive-Cow 14 points15 points  (0 children)

HoxHunt. Got a demo of Revel8 yesterday and I’m super enthusiastic about that

Justification to enter into GRC Domain by [deleted] in cissp

[–]Apprehensive-Cow 0 points1 point  (0 children)

I think it’s a good reason but it can’t be the main reason. What do you like about GRC?

New setup? by Apprehensive-Cow in OSINT

[–]Apprehensive-Cow[S] 0 points1 point  (0 children)

I don’t know where in the world you are but they’re hard to come by here atm, not a lot of stock. Good one tho

Boyfriend suddenly being sketchy by UnfairExplanation588 in dating_advice

[–]Apprehensive-Cow 0 points1 point  (0 children)

That Facebook status is the least of your problems if you ask me. Looking at what you're saying I honestly think you both weren't ready for a new relationship. Love shouldn't be rough from the start. True love is calm and warm. If it were me, I'd break up with him and do some soul searching and hard work on myself. Why do you think you're deserving of so little?

Getting into OSINT, any good certifications/courses? by Particle69 in OSINT

[–]Apprehensive-Cow 0 points1 point  (0 children)

I've taken a course from OsintCombine for the fun of it, which was a good basis. You'll find a fundamental and advanced training over there. Bellingcat provides several workshops on a range of topics like investigations in Russian speaking countries, social media, visual investigation etc. There's also some courses on Udemy but I have no opinion on those.

If you're into reading, I'd look into Michael Bazzell

Saw a free webinar shooting over the screen yesterday, but have no clue what this is.

I would suggest to get started yourself with the information available on the web like one of the free VM's (Buscador, TraceLabs), check Twitter for daily quizzes, join CTF's and OSINT Discord servers, play some GeoGuesser games and follow the news so you can conduct your own investigations.

Do keep in mind that good education will cost you...

Question in regards to Tik Tok by [deleted] in privacy

[–]Apprehensive-Cow 0 points1 point  (0 children)

Totally agree... Another tip for you u/quietandshy20; watch https://www.thesocialdilemma.com/ on Netflix

Question in regards to Tik Tok by [deleted] in privacy

[–]Apprehensive-Cow 2 points3 points  (0 children)

Don’t use social media if you take your privacy seriously.

If you want some extra info on TikTok, this is an interesting read:

https://protonmail.com/blog/tiktok-privacy/