< ciso
brief />
Tag Banner

All news with #iso 27001 tag

23 articles

Practical IAM Compliance: Requirements and Best Practices

🔐 This guide defines IAM compliance as proving that identity and access controls are not only documented but enforced across users, applications, infrastructure, and non-human identities. It explains key obligations from frameworks like SOX, PCI DSS, HIPAA, ISO/IEC 27001, NIST SP 800-53, and GDPR, and highlights evidence gaps between policy intent and runtime execution. The article outlines core controls—least privilege, segregation of duties, MFA, lifecycle management—and urges continuous, application-layer verification rather than periodic reviews.
read more →

AWS PCS expands security and compliance coverage

🔒 AWS Parallel Computing Service (PCS) has broadened its compliance posture to support regulated workloads. PCS is now in scope for FedRAMP Class C in US East (Ohio), US East (N. Virginia), and US West (Oregon), and FedRAMP Class D in AWS GovCloud (US). PCS is included in SOC 1/2/3 reports, ISO certifications, CSA STAR (CCM 4.0), PCI attestations, and is HIPAA eligible, enabling sensitive HPC workloads on AWS.
read more →

AWS expands ISO and CSA STAR scope to two services

🔒 Amazon Web Services completed an onboarding audit reissued on May 31, 2026, covering ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, 22301:2019 and CSA STAR CCM v4.0. EY Certify Point conducted the audit with no findings to add two additional AWS services into the certification scope. These certifications reflect AWS’s ongoing commitment to robust security controls and customer data protection across services. Customers can view full lists and access certificates via the AWS Management Console through AWS Artifact.
read more →

AWS Completes S&P Global KY3P Assessment Report

🔒 AWS has completed the S&P Global Know Your Third Party (KY3P) assessment to validate its security posture and help customers reduce supplier due diligence. The KY3P assessment is evidence-based and evaluates operation of controls across privacy, network, access, and physical security domains. Results can be mapped to frameworks such as NIST CSF v2, PCI DSS 4.0, and ISO 27001:2022 to provide customers with standardized risk data and improved visibility into supply chain risks.
read more →

AWS Achieves SNI 27017, 27018 and 9001 in Jakarta Region

🔒 AWS earned three SNI certifications for the Asia Pacific (Jakarta) Region: SNI ISO/IEC 27017:2015, SNI ISO/IEC 27018:2019, and SNI ISO 9001:2015. An independent auditor accredited by KAN assessed the controls against local requirements. Combined with the 2023 SNI ISO/IEC 27001, AWS is the first cloud provider to hold all four SNI certifications. Certificates are available in AWS Artifact.
read more →

ISO 31000:2018 Risk Management on AWS — Practical Guide

🛡️ AWS Security Assurance Services has published a new compliance guide, ISO 31000:2018 Risk Management on AWS, offering practical guidance for building and operating risk management programs in AWS environments. The guide explains how to apply ISO 31000:2018 principles to establish context, perform risk assessments, implement treatments, and enable continuous monitoring. It highlights governance aligned with the AWS Shared Responsibility Model and recommends strategies for avoidance, mitigation, transfer, and acceptance to support scalable, automated security and compliance.
read more →

New ISO/IEC 27001:2022 Compliance Guide for AWS Customers

🔒 AWS released the ISO/IEC 27001:2022 on AWS compliance guide to help organizations design and operate an Information Security Management System (ISMS) using AWS services. The guide maps selected Annex A controls and clauses 4–10 to AWS services and architectural capabilities, and clarifies customer responsibilities under the Shared Responsibility Model. It provides practical recommendations for evidence collection, documentation, automation, and audit readiness using AWS native tooling. The target audience includes cloud architects, security teams, compliance leaders, and DevOps practitioners seeking certification readiness.
read more →

AWS European Sovereign Cloud Achieves Initial Certifications

🛡️ The AWS European Sovereign Cloud has published initial independent assurances including SOC 2 Type 1 and C5 Type 1 attestations plus seven ISO certifications covering 69 services. Announced after general availability in January 2026, these reports validate control design and implementation mapped to the ESC-SRF, with EU-resident operations and strict data residency. Customers can access the reports via AWS Artifact; AWS plans to expand coverage over time.
read more →

AWS Adds Taipei Region and AWS Deadline Cloud to ISO/CSA

🔒 AWS completed its annual recertification audit with no findings, extending its ISO and CSA STAR coverage. The update adds the Asia Pacific (Taipei) Region and AWS Deadline Cloud to the scope and reconfirms compliance with standards including ISO 9001, 27001, 27017, 27018, 27701, 20000-1, and 22301. These certifications underscore AWS's commitment to robust security, privacy, and service management controls. Customers can view certificates via AWS Artifact or the AWS ISO and CSA STAR Certified page.
read more →

GCHQ Seeks CISO for Under 130,000 GBP Amid Skills Shortage

🔐 A recent job posting from GCHQ for a Chief Information Security Officer has drawn industry attention for offering a maximum salary of £130,000 (roughly €150k–€155k) despite demanding executive-level responsibilities. The role requires deep expertise in securing cloud environments, emerging technologies and compliance with frameworks such as NIST, ISO 27001, GDPR and GovS 007. Desired certifications include CISSP, CISM or CCISO. Observers note the posting highlights the gap between public sector compensation and market rates amid a global cybersecurity skills shortage.
read more →

GCHQ CISO Role Offers Surprisingly Low Salary for Nation

⚠️ A recent GCHQ job advertisement seeks a chief information security officer described as one of the most influential cyber security leadership roles in the UK, yet it offers a maximum salary of £130,000 (about $175,000). The role asks for expertise securing cloud environments and emerging technologies, and knowledge of frameworks such as NIST, ISO 27001, GDPR and GovS 007. Professional certifications like CISSP, CISM or CCISO are flagged as highly desirable. The compensation and absence of industry-style incentives have prompted criticism amid a global shortage of security talent.
read more →

13 Questions CISOs Should Ask Third-Party Vendors Now

🔒 Increasing reliance on third-party IT and software significantly expands an organization’s attack surface, and security leaders must act before incidents force their involvement. The article provides a focused checklist of 13 practical questions for CISOs covering evidence of controls (e.g., SOC 2 Type II, ISO/IEC 27001), change management, identity posture, and workflow validation. It stresses independent testing, clear contractual responsibilities, timely incident notification, and rigorous handling of OAuth and API integrations to reduce supply-chain risk.
read more →

Passwords to Passkeys: ISO 27001 Compliance Practical Guide

🔐 Password-based authentication is increasingly replaced by passkeys—FIDO2/WebAuthn-backed credentials that store private keys on devices and typically meet AAL2/AAL3 assurance per NIST SP 800-63B. This article explains how organizations can adopt passkeys while remaining compliant with ISO/IEC 27001, mapping changes to Annex A controls (Access Control, Authentication Information, Secure Authentication) and documenting risk treatment. It highlights benefits, common risks such as device loss and downgrade attacks, and practical migration steps for enterprise deployment.
read more →

CISOs: Move Beyond Compliance to Anticipate Risk in 2026

🔒 CISOs entering 2026 should treat compliance as a baseline, not a destination. While frameworks like HIPAA, SOC 2 and ISO 27001 provide essential controls, relying solely on checklists breeds complacency and misses evolving threats such as AI-enabled attacks, third-party failures and future quantum risks. Adopt longer time horizons, scenario-based risk assessments and financial impact modelling to align security with business priorities and secure board support.
read more →

13 Questions to Vet IT Vendors and Reduce Third-Party Risk

🔐 As enterprises outsource more IT and adopt third-party SaaS, recent high-profile breaches show attackers are exploiting vendor trust pathways like help desks, OAuth tokens, and permissive integrations. CSOs should treat vendor selection as continuous risk management and demand strong attestations (e.g., SOC 2 Type II, ISO/IEC 27001), inventories of OAuth/API relationships, and evidence of actual workflow execution. The article lists 13 targeted questions covering controls, notification commitments, testing cadence, isolation measures, and insurance to reduce supply-chain risk.
read more →

AWS Landing Zone Accelerator: Universal Configuration

🔒 AWS has released the Landing Zone Accelerator on AWS sample security baseline called the Universal Configuration, designed to deploy a secure, multi-account environment rapidly. It encodes AWS Well‑Architected security best practices and automates hundreds of controls to accelerate compliance for regulated workloads. The release is paired with the LZA Compliance Workbook on AWS Artifact, which maps technical controls to frameworks such as NIST, ISO, HIPAA, and CMMC.
read more →

Why ISO and ISMS Certifications Fail: Nine Common Pitfalls

🔒 Implementation and certification of ISO standards or an ISMS frequently falter due to avoidable organizational and technical mistakes. The article outlines nine recurring issues — from weak management sponsorship and treating certification as a one‑off task to poor employee engagement, inadequate skills development, dishonest assessments, and insufficient follow‑up. For each pitfall it recommends practical remedies such as executive commitment, clear planning, targeted training, honest risk analysis, automation where appropriate, and adequate resourcing to make the management system functional and sustainable.
read more →

Why ISO/ISMS Security Certifications Often Fail and How

🛡️ Many ISO and ISMS certification efforts falter not because the standards are unclear but because organisations treat certification as a one-off checkbox activity rather than embedding controls into daily operations. Common failures include weak senior leadership commitment, insufficient employee involvement and training, wishful thinking about risks, and underinvestment in proper implementation. Practical remedies include clear planning, honest risk assessment, executive sponsorship, targeted competency building, and treating the ISMS as a continuous process rather than a closed project.
read more →

Rethinking Service Provider Risk: A CISO Imperative

🔍 As organizations outsource more critical systems and security functions to managed service providers, the complexity and frequency of third-party incidents are rising — 47% of organizations reported a third-party breach in the 12 months to mid-2025. Security leaders must balance rigorous, standards-based assurance (for example ISO 27001 or SOC 2) with relationship-driven vetting that fosters transparency and shared responsibility. Experts from media company Advance, the University of Queensland and vendor advisors argue that questionnaires alone are insufficient: meaningful dialogue, selective disclosure (summaries of pen tests rather than full reports), contractual clarity, and AI-aware controls are all needed to assess and manage evolving risks.
read more →

Six IT Risk-Assessment Frameworks for Enterprise Governance

🛡️ This article summarizes six prominent IT risk-assessment frameworks—COBIT, FAIR, ISO/IEC 27001, NIST RMF, OCTAVE and TARA—and explains their core purpose and methods. It contrasts governance-oriented, standards-based, lifecycle and threat-centric approaches and highlights where quantitative analysis or certification focus applies. The overview helps security and IT leaders identify which model or combination of models best fits organizational needs.
read more →