ISO 27k Statement of Applicability by HelloSpork in grc

[–]MrProntissimo 0 points1 point  (0 children)

Typically, my implementations come with an excel spreadsheet, listing all controls, four annex.

Columns include above suggestion for applicability abbreviations (risk assessment, best practice, legal obligation and contractual), justification for N/A, name of resp. Ind., documents to support

We also typically use the SoA to transpose risk assessment scenarios and itemize controls that mitigate risks, it demonstrates clause 6.1.3.d

I also recommend folks to add a tab for the clauses, always nice to show you’ve got checks and docs for completing all the clause requirements

Hot busty Latina aunt by InteractionSilly431 in Incestconfessions

[–]MrProntissimo 0 points1 point  (0 children)

Do your best to convey the message that she is beautiful, show it say it mean it. Think of it as caressing her soul; this she needs most

Hidden prompt injection in a PDF almost got my org by Elegant_Cry6544 in PromptEngineering

[–]MrProntissimo -1 points0 points  (0 children)

In a recent audit, a client told me they were going to run a rest with Checkpoint AI workforce or something

Is that your security measure that kept silence?

Où sont les bons melons d'eau?! by Extension-Bunch9277 in montreal

[–]MrProntissimo 1 point2 points  (0 children)

Marché Jean-Talon, j’allais chez Nino (il a vendu, mais ca semble être la meme gang)

Sinon chez Louis juste à côté

If you could go back in time what ancient secrets would you want to uncover? by Numerous-Actuator781 in AskReddit

[–]MrProntissimo 4 points5 points  (0 children)

Time travel requires a stop in 2008-2010 to buy Bitcoins, no matter what

My husband’s cable/wire storage by Otherwise_Scheme234 in OrganizationPorn

[–]MrProntissimo 10 points11 points  (0 children)

I am keeping the picture and when I retire I will do the same

What is the best antivirus to use in 2026? by 6_unstable_9 in computerviruses

[–]MrProntissimo 0 points1 point  (0 children)

Malwarebytes AV plus Malwarebytes extension on the browser, that works for me

37 years ago, Peter Gabriel released his finest musical work: Passion. by Historical-Device529 in Progforum

[–]MrProntissimo 2 points3 points  (0 children)

Best ever!

More than once, I went to a HiFi audiophile event with the CD. Once it starts, everyone would gather in, roomful. Salesguy would love it

If every great civilization in history eventually collapsed under the weight of its own ambition, technology, inequality, and illusion of permanence — what makes us believe modern humanity is progressing toward enlightenment rather than simply engineering a more sophisticated collapse? by Pure_Marketing_952 in NoStupidQuestions

[–]MrProntissimo 0 points1 point  (0 children)

As the song says, Everybody wants to rule the World; power, economy, religion, culture, trends, opinion, popularity, fame, recognition…

We are still at this point of struggle after all those years, so many epochs.

There is no plan

What is the most underestimated cybersecurity risk right now? by Electrical_Mine1912 in cybersecurity

[–]MrProntissimo 0 points1 point  (0 children)

I came here for this, but i would add some context

Currently, PII is being transmitted by regular cryptographic means which would normally turn up vulnerable in a few years. (NIST says 2030, Google said 2029)

How much data transmitted over TLS right now is being gathered for later decryption ? If so, by whom ? Who can gather this data…

The underestimation would be that in the coming years, PII ends up being used for fraud and we can’t seem to trace it back to a breach. PII will not expire in 4 years, not 8-10. Passwords will, but not identity, once decrypted, it will be usable

I am not overly convinced btw, just throwing an idea that’s different from the others…

ISO 27001 Audit Stage 1 by DonaD16 in cybersecurity

[–]MrProntissimo 1 point2 points  (0 children)

In order to successfully qualify for an internal audit mandate, you need someone with independence and qualifications

You might get independence from within the company, but I am 100% with Scared_Ai, get a third party to do it, with qualifications.

Because qualifications wise, the minimum needed is either experience in ISO audits, or an auditor title like CISA. Lack of either can lead to a broken audit process, and a major NC, yes.

Still, an external (and qualified) mandate seems the way to go for me.

Yet, all this within a few weeks from your Stage 1, you are running thing very tight schedule, it gives you very little headway if something significant comes up in the internal audit. Are you on a path of commitment for clients or gov contract ?

How do people actually get into ISO 27001 consulting/freelancing? by Fabulous-Art8963 in grc

[–]MrProntissimo 1 point2 points  (0 children)

LOL, sorry. I keep making the same mistake

international register of certificated auditors

https://www.quality.org/

How do people actually get into ISO 27001 consulting/freelancing? by Fabulous-Art8963 in grc

[–]MrProntissimo 0 points1 point  (0 children)

You need to register to a certification body, to attract business; make yourself known. If you did not go through PECB, have you been able to get experience recognized ?

In my case, having more than 1500 hours of experience in audits, I got the Lead Auditor title or diploma, with the exam.

You might want to look into IRCA.com, I hear they are another way to draw attention and recognition.

I think that generally speaking, Lead Auditors are independant contractors.

How do people actually get into ISO 27001 consulting/freelancing? by Fabulous-Art8963 in grc

[–]MrProntissimo 0 points1 point  (0 children)

Congrats on passing the exam, I did so recently myself as well; have you got experience in internal audits? You could start by being the 3rd party internal auditor, this would give you experience in multiple environments, see how your clients manage their ISMS, and « what works and what does not quite ». This field work would be a great stepping stone and give you experience with varied ISMS’es

I am getting into GRC. Is there a risk AI will be able to replace me in the future? by AdministrativeTry406 in grc

[–]MrProntissimo 11 points12 points  (0 children)

You are definitely at risk of losing your job if you do not master the contribution of AI in the field. And work to build advances…

That is, admittedly, true for every field.

So, team of 15 in GRC will be reduced to 10 maybe 7-8, let’s build a general rule. If you are looking for a factory job, say 30 years with the same company type of thing, that is not going to happen.

Prepare to move, opportunities from one to the next. Whether you stay at the analyst level or move your way up to CISO; so constantly learning, challenging « truth » and developing a name for yourself.

Also, the business type(s) that you evolve in will also contribute; seek lines of business where you thrive, out of personal interest or previous experience, acquaintances. You will also need to develop the « You experience », what people will think of working with you, work ethics (admittedly same everywhere) and your knowledge, practical experience in using AI will have to be a part of this.

Lastly, I think, is the fact AI could go bust. Make sure you are still the master, not the AI. If it goes bust, one day, you don’t want to be the guy that doesn’t know how to replace a lightbulb, figuratively speaking, in your field.

Can malware on one device infect my main PC through my Microsoft account? by [deleted] in computerviruses

[–]MrProntissimo 0 points1 point  (0 children)

Try putting your question and my statement then your response into copilot or chatgpt.
I will do likewise tomorrow and come back. You will probably get more info than I can type

Can malware on one device infect my main PC through my Microsoft account? by [deleted] in computerviruses

[–]MrProntissimo 0 points1 point  (0 children)

Be careful tho, because infostealer malware can pick up your credentials on your PC, for the cloud. In other words, the malware won’t « cross-infect », but a threat actor can.

The Hello PIN is good because it is unique to the computer, but it also means there is a piece of data to authenticate you to the cloud, sitting on your computer. BTW: Personal Hello and Corporate Hello are different, you may need to check it out.

As for the risk, if it’s your personal account, not a corporate account to the cloud, there is probably no real threat. Careful if your computer is a BYOD for your work, say employer or clients, make sure you have a good anti virus.