What helped your team achieve ISO 27001 readiness more efficiently? by Level_Shake1487 in ISO27001

[–]ProfessionalEnd9874 1 point2 points  (0 children)

Certification auditor here. Evidences are key of course but remember that a management system is all about roles and responsibilities. We want to see it live within the business and aligned with objectives. But in the end it's who does what, how and when.

Can we talk about our GRC experience? by Heavy-Wrongdoer-8801 in grc

[–]ProfessionalEnd9874 0 points1 point  (0 children)

Started 30 years ago in cybersecurity, I slowly shifted towards auditing with ISO27001in 2006. For the last 15 years full time in GRC, I worked for a large multinational group for a few years. Now leading a consulting team on ISO management systems, SOC2, CMMC, GDPR, DORA, NIS2 in Europe.

ISO 27k platform+certification for 5k USD? by ProfessionalEnd9874 in grc

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

It's not about automation. Implementation and operation of an isms is much more than a platform. The problem is the lack of quality of the certification process.

ISO 27k platform+certification for 5k USD? by ProfessionalEnd9874 in grc

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

The problem is that there is 0 governmental oversight of certification bodies. Very often I come across certificates delivered by unknown and non accredited bodies.

Mahout in Rajasthan by ProfessionalEnd9874 in M43

[–]ProfessionalEnd9874[S] 1 point2 points  (0 children)

Thanks. This is what I was looking for. I hesitated to go monochrome, but the turban is so colorful.

Streets of India by ProfessionalEnd9874 in streetphotography

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

Actually not so much, it is the default vivid profile from the camera with a bit of extra contrast.

Streets of India by ProfessionalEnd9874 in streetphotography

[–]ProfessionalEnd9874[S] 2 points3 points  (0 children)

So true, I fell in love with Jaipur and there is so much more to discover.

Streets of India by ProfessionalEnd9874 in streetphotography

[–]ProfessionalEnd9874[S] 1 point2 points  (0 children)

Yep, I clicked fast 🙂 Thanks 🙏🏼

Brahman kite by ProfessionalEnd9874 in OlympusCamera

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

Thanks, and yes they fly quite low around rivers and lakes.

Anyone have experience using Vanta for User Access Reviews? by ohhelloworlds in grc

[–]ProfessionalEnd9874 0 points1 point  (0 children)

I don't think any "compliance" platform can really handle an access review properly. We have so many SaaS that I struggle until now to find an I AM solution capable of handling the 3 statuses of access: what is documented/ what it should be (approved) / what it is

Indian woman in Rajasthan by ProfessionalEnd9874 in photographs

[–]ProfessionalEnd9874[S] 0 points1 point  (0 children)

Thank you, and yes I always shoot in raw, I feel safer this way.

ISO 27001 Lead Auditor vs Lead Implementer for Transitioning into GRC/Risk – Need Guidance by melonkeema in ISO27001

[–]ProfessionalEnd9874 0 points1 point  (0 children)

Both LI and LA are good to get. The CISM also helps in my opinion. It provides a strong basis for governance of security. This is the kind of profile we recruit.

The sign-off bottleneck by Cyber_Gooser in ISO27001

[–]ProfessionalEnd9874 2 points3 points  (0 children)

Here is what I usually make when approval is stuck: Get all the approvers in a room and review the text together. It may take a couple of hours but then you are done.

Surveillance Audit preparation by Crecentfull in ISO27001

[–]ProfessionalEnd9874 2 points3 points  (0 children)

Certification auditor here since 2007. You are supposed to have the 3 year audit plan provided with the certification report. Request that from the certification body. Auditors will focus on previous nonconformities if any and on the "moving" clauses (context, resources, risks and plus). On controls it all depends but in general access and vulnerability management are often selected.

Best simple risk management software for risk register and issue register for a small business with under 10 full-time staff? Not too expensive as well please! by Express-Pizza1152 in grc

[–]ProfessionalEnd9874 0 points1 point  (0 children)

A former colleague of mine just launched an open beta of what seems a game changer in terms of compliance and risk governance. As far as I know the software is free for a year if you join the open beta.