Confused about how ISO 27001 and the new AI standard, ISO 42001 work together? In this post we provide a simple, plain English overview of what ISO 42001 is and why you should care.
Why Colleges need to consider ISO27001
ISO 27001 is a standard that can help many organisations, including Colleges and Universities. In this blog we explore why Colleges are most at risk from attack.
ISO27001:2022 – FAQ
Audit tests and other assurance activities involving assessment of operational systems need to be planned and agreed between the tester and appropriate management. But what kind of protection is needed?
ISO27001:2022 – A7.2 – Physical entry controls
Audit tests and other assurance activities involving assessment of operational systems need to be planned and agreed between the tester and appropriate management. But what kind of protection is needed?
ISO27001:2022 – A7.5 – Protecting against physical and environmental threats
Secure coding principles needs to be applied to software development, but what are these principles and how far do you need to go? Let’s take a look at what A8.28 expects.
ISO27001:2022 – A5.6 – Contact with special interest groups
Audit tests and other assurance activities involving assessment of operational systems need to be planned and agreed between the tester and appropriate management. But what kind of protection is needed?
ISO27001:2022 – A8.34 – Protection of information systems during audit and testing
Audit tests and other assurance activities involving assessment of operational systems need to be planned and agreed between the tester and appropriate management. But what kind of protection is needed?
ISO27001:2022 – A8.33 – Test information
This control states that test information shall be appropriately selected, protected and managed. But how do you do that, and why is this so important?Let’s look at this control a little closer.
ISO27001:2022 – A8.32 – Change management
Changes to information processing facilities and information systems need to be subject to change management procedures, but how do you do this without slowing down your business? Let’s take a look.
ISO27001:2022 – A8.31 – Separation of development, test and production environments
Development, testing and production environments need to be separated and secured, but how do you do this in practice? What does ‘separate’ actually mean in the real world?








