olivLaw · Feed
From booksOCEG (Open Compliance and Ethics Group)· 7 Sept, 10:51
Question

Which word in the OCEG definition separates GRC from three functions working separately?

GRC is not a department but the property of not having three different truths about the same control.

OCEG (Open Compliance and Ethics Group) · What Is GRC (Governance, Risk, and Compliance)?

From booksNational Institute of Standards and Technology (NIST)· 7 Sept, 04:51
Question

What did version 2.0 of the NIST framework change, and why is the new function placed at the centre?

Governance is not an extra heading but the function that decides how all the others are applied.

National Institute of Standards and Technology (NIST) · The NIST Cybersecurity Framework (CSF) 2.0

From booksNational Institute of Standards and Technology (NIST)· 6 Sept, 22:51
Question

What is the difference between risk appetite and risk tolerance?

A risk owner is someone who can allocate budget and stop an activity, not someone who keeps a register.

National Institute of Standards and Technology (NIST) · Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1)

From booksBruce Schneier· 6 Sept, 16:51
Question

What simple test shows a control is real rather than merely prepared for the audit?

The certificate is a photograph, and security is the film it was cut from.

Bruce Schneier · The Process of Security

From booksThe Institute of Internal Auditors (IIA)· 6 Sept, 10:51
Question

Which line does the information security officer sit on, and why can they not give assurance?

Nobody can give independent assurance over their own work, however competent they are.

The Institute of Internal Auditors (IIA) · The IIA's Three Lines Model: An Update of the Three Lines of Defense

From booksWilliam Thomson (Lord Kelvin)· 6 Sept, 04:51
Question

What does clause 9.1 of ISO/IEC 27001:2022 explicitly require, beyond the instruction to measure?

A performance indicator describes what happened, while a risk indicator moves before it happens.

William Thomson (Lord Kelvin) · Electrical Units of Measurement

From booksRichard P. Feynman· 5 Sept, 22:51
Question

What turns a statement about a control into objective evidence?

What cannot be shown to a stranger did not happen, as far as the audit is concerned.

Richard P. Feynman · Cargo Cult Science

From booksISO/IEC· 5 Sept, 16:51
Question

Why is ISO/IEC 27001 a management system standard rather than a catalogue of controls?

Annex A is the consequence of the risk assessment, not the starting point of the implementation.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksISO/IEC· 5 Sept, 10:51
Question

What must be taken into account when determining the scope, under clause 4.3?

A scope too narrow passes the audit but convinces no customer, and one too broad never gets finished.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksISO/IEC· 5 Sept, 04:51
Question

Which two responsibilities must top management assign outright under 5.3?

Clause 5 is audited in the executive office, not in the server room.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksISO/IEC· 4 Sept, 22:51
Question

What is the difference between risk analysis and risk evaluation?

Criteria are written before the risks, otherwise the threshold moves to fit the result.

ISO/IEC · ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks

From booksISO/IEC· 4 Sept, 16:51
Question

What must the Statement of Applicability say about a necessary control that is not yet implemented?

Annex A is the safety net under your list of controls, not its source.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksISO/IEC· 4 Sept, 10:51
Question

What does clause 6.3, new in the 2022 edition, require?

An objective that cannot be measured is an intention on letterhead.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksISO/IEC· 4 Sept, 04:51
Question

What does ISO/IEC 27001:2022 require about outsourced processes?

Clause 6 writes the method, clause 8 proves it was used.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksISO· 3 Sept, 22:51
Question

Why can the very person who implemented a process not audit it internally?

An audit without independence produces calm, not assurance.

ISO · ISO 19011:2026 — Guidelines for auditing management systems

From booksW. Edwards Deming· 3 Sept, 16:51
Question

What is the difference between a correction and a corrective action?

A closed ticket is not an eliminated cause.

W. Edwards Deming · Out of the Crisis

From booksISO/IEC· 3 Sept, 10:51
Question

How many controls are in Annex A of ISO/IEC 27001:2022 and how are they grouped?

Annex A is a checklist, not a shopping list.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

From booksSun Tzu, traducere Lionel Giles· 3 Sept, 04:51
Question

Which three columns does a useful gap analysis have?

A gap analysis without owners and deadlines is a list of regrets.

Sun Tzu, traducere Lionel Giles · The Art of War

From booksRonald Reagan· 2 Sept, 22:51
Question

What is checked in stage 1 and what is checked in stage 2?

Stage 1 judges the documents, stage 2 judges the evidence, and accreditation judges the body that judges both.

Ronald Reagan · Remarks on Signing the Intermediate-Range Nuclear Forces Treaty

From booksISO· 2 Sept, 16:51
Question

What are the four parts of the response to a nonconformity?

A major nonconformity is closed with a root cause and a demonstrated corrective action, not with a correction.

ISO · ISO 19011:2018 — Guidelines for auditing management systems

Loading…