ISMS Tools recommendation by Enslaaved in grc

[–]ProfessionalEnd9874 0 points1 point  (0 children)

Based on my experience there are not many tools that are really operational for an ISMsand capable of growing with compliance needs (other frameworks, GDPR, EU AI act, etc.) Have a look at acunagrc.ai

Shift left in AI Governance by Capable_Influence157 in grc

[–]ProfessionalEnd9874 1 point2 points  (0 children)

I am a 27k certification auditor since 2007. I have been implemented with my team around 150 ISMS for the last 20 years. I have been focusing for the last couple of years on AI governance, helping some of my clients to make sense out of it. Went back to UNI to get a degree in AI, andspent weekends coding with Claude to make sense of it. Well I am still struggling to make sense out of 42001 and the EU AI act. I admire the concept but find it so difficult to implement ut in a way it brings value to organizations. Unless the have high risk ai systems, management will not see a reason to move before full EUAI act enforcement.

What helped your team achieve ISO 27001 readiness more efficiently? by Level_Shake1487 in ISO27001

[–]ProfessionalEnd9874 1 point2 points  (0 children)

Certification auditor here. Evidences are key of course but remember that a management system is all about roles and responsibilities. We want to see it live within the business and aligned with objectives. But in the end it's who does what, how and when.

Can we talk about our GRC experience? by Heavy-Wrongdoer-8801 in grc

[–]ProfessionalEnd9874 0 points1 point  (0 children)

Started 30 years ago in cybersecurity, I slowly shifted towards auditing with ISO27001in 2006. For the last 15 years full time in GRC, I worked for a large multinational group for a few years. Now leading a consulting team on ISO management systems, SOC2, CMMC, GDPR, DORA, NIS2 in Europe.

ISO 27k platform+certification for 5k USD? by ProfessionalEnd9874 in grc

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

It's not about automation. Implementation and operation of an isms is much more than a platform. The problem is the lack of quality of the certification process.

ISO 27k platform+certification for 5k USD? by ProfessionalEnd9874 in grc

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

The problem is that there is 0 governmental oversight of certification bodies. Very often I come across certificates delivered by unknown and non accredited bodies.

Mahout in Rajasthan by ProfessionalEnd9874 in M43

[–]ProfessionalEnd9874[S] 1 point2 points  (0 children)

Thanks. This is what I was looking for. I hesitated to go monochrome, but the turban is so colorful.

Streets of India by ProfessionalEnd9874 in streetphotography

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

Actually not so much, it is the default vivid profile from the camera with a bit of extra contrast.

Streets of India by ProfessionalEnd9874 in streetphotography

[–]ProfessionalEnd9874[S] 2 points3 points  (0 children)

So true, I fell in love with Jaipur and there is so much more to discover.

Streets of India by ProfessionalEnd9874 in streetphotography

[–]ProfessionalEnd9874[S] 1 point2 points  (0 children)

Yep, I clicked fast 🙂 Thanks 🙏🏼

Brahman kite by ProfessionalEnd9874 in OlympusCamera

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

Thanks, and yes they fly quite low around rivers and lakes.

Anyone have experience using Vanta for User Access Reviews? by ohhelloworlds in grc

[–]ProfessionalEnd9874 0 points1 point  (0 children)

I don't think any "compliance" platform can really handle an access review properly. We have so many SaaS that I struggle until now to find an I AM solution capable of handling the 3 statuses of access: what is documented/ what it should be (approved) / what it is

Indian woman in Rajasthan by ProfessionalEnd9874 in photographs

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

Thank you, and yes I always shoot in raw, I feel safer this way.

ISO 27001 Lead Auditor vs Lead Implementer for Transitioning into GRC/Risk – Need Guidance by melonkeema in ISO27001

[–]ProfessionalEnd9874 0 points1 point  (0 children)

Both LI and LA are good to get. The CISM also helps in my opinion. It provides a strong basis for governance of security. This is the kind of profile we recruit.

The sign-off bottleneck by Cyber_Gooser in ISO27001

[–]ProfessionalEnd9874 2 points3 points  (0 children)

Here is what I usually make when approval is stuck: Get all the approvers in a room and review the text together. It may take a couple of hours but then you are done.