< ciso
brief />
Tag Banner

All news with #iso 27001 tag

20 articles

AWS Completes S&P Global KY3P Assessment Report

🔒 AWS has completed the S&P Global Know Your Third Party (KY3P) assessment to validate its security posture and help customers reduce supplier due diligence. The KY3P assessment is evidence-based and evaluates operation of controls across privacy, network, access, and physical security domains. Results can be mapped to frameworks such as NIST CSF v2, PCI DSS 4.0, and ISO 27001:2022 to provide customers with standardized risk data and improved visibility into supply chain risks.
read more →

AWS Achieves SNI 27017, 27018 and 9001 in Jakarta Region

🔒 AWS earned three SNI certifications for the Asia Pacific (Jakarta) Region: SNI ISO/IEC 27017:2015, SNI ISO/IEC 27018:2019, and SNI ISO 9001:2015. An independent auditor accredited by KAN assessed the controls against local requirements. Combined with the 2023 SNI ISO/IEC 27001, AWS is the first cloud provider to hold all four SNI certifications. Certificates are available in AWS Artifact.
read more →

ISO 31000:2018 Risk Management on AWS — Practical Guide

🛡️ AWS Security Assurance Services has published a new compliance guide, ISO 31000:2018 Risk Management on AWS, offering practical guidance for building and operating risk management programs in AWS environments. The guide explains how to apply ISO 31000:2018 principles to establish context, perform risk assessments, implement treatments, and enable continuous monitoring. It highlights governance aligned with the AWS Shared Responsibility Model and recommends strategies for avoidance, mitigation, transfer, and acceptance to support scalable, automated security and compliance.
read more →

New ISO/IEC 27001:2022 Compliance Guide for AWS Customers

🔒 AWS released the ISO/IEC 27001:2022 on AWS compliance guide to help organizations design and operate an Information Security Management System (ISMS) using AWS services. The guide maps selected Annex A controls and clauses 4–10 to AWS services and architectural capabilities, and clarifies customer responsibilities under the Shared Responsibility Model. It provides practical recommendations for evidence collection, documentation, automation, and audit readiness using AWS native tooling. The target audience includes cloud architects, security teams, compliance leaders, and DevOps practitioners seeking certification readiness.
read more →

AWS European Sovereign Cloud Achieves Initial Certifications

🛡️ The AWS European Sovereign Cloud has published initial independent assurances including SOC 2 Type 1 and C5 Type 1 attestations plus seven ISO certifications covering 69 services. Announced after general availability in January 2026, these reports validate control design and implementation mapped to the ESC-SRF, with EU-resident operations and strict data residency. Customers can access the reports via AWS Artifact; AWS plans to expand coverage over time.
read more →

AWS Adds Taipei Region and AWS Deadline Cloud to ISO/CSA

🔒 AWS completed its annual recertification audit with no findings, extending its ISO and CSA STAR coverage. The update adds the Asia Pacific (Taipei) Region and AWS Deadline Cloud to the scope and reconfirms compliance with standards including ISO 9001, 27001, 27017, 27018, 27701, 20000-1, and 22301. These certifications underscore AWS's commitment to robust security, privacy, and service management controls. Customers can view certificates via AWS Artifact or the AWS ISO and CSA STAR Certified page.
read more →

GCHQ Seeks CISO for Under 130,000 GBP Amid Skills Shortage

🔐 A recent job posting from GCHQ for a Chief Information Security Officer has drawn industry attention for offering a maximum salary of £130,000 (roughly €150k–€155k) despite demanding executive-level responsibilities. The role requires deep expertise in securing cloud environments, emerging technologies and compliance with frameworks such as NIST, ISO 27001, GDPR and GovS 007. Desired certifications include CISSP, CISM or CCISO. Observers note the posting highlights the gap between public sector compensation and market rates amid a global cybersecurity skills shortage.
read more →

GCHQ CISO Role Offers Surprisingly Low Salary for Nation

⚠️ A recent GCHQ job advertisement seeks a chief information security officer described as one of the most influential cyber security leadership roles in the UK, yet it offers a maximum salary of £130,000 (about $175,000). The role asks for expertise securing cloud environments and emerging technologies, and knowledge of frameworks such as NIST, ISO 27001, GDPR and GovS 007. Professional certifications like CISSP, CISM or CCISO are flagged as highly desirable. The compensation and absence of industry-style incentives have prompted criticism amid a global shortage of security talent.
read more →

13 Questions CISOs Should Ask Third-Party Vendors Now

🔒 Increasing reliance on third-party IT and software significantly expands an organization’s attack surface, and security leaders must act before incidents force their involvement. The article provides a focused checklist of 13 practical questions for CISOs covering evidence of controls (e.g., SOC 2 Type II, ISO/IEC 27001), change management, identity posture, and workflow validation. It stresses independent testing, clear contractual responsibilities, timely incident notification, and rigorous handling of OAuth and API integrations to reduce supply-chain risk.
read more →

Passwords to Passkeys: ISO 27001 Compliance Practical Guide

🔐 Password-based authentication is increasingly replaced by passkeys—FIDO2/WebAuthn-backed credentials that store private keys on devices and typically meet AAL2/AAL3 assurance per NIST SP 800-63B. This article explains how organizations can adopt passkeys while remaining compliant with ISO/IEC 27001, mapping changes to Annex A controls (Access Control, Authentication Information, Secure Authentication) and documenting risk treatment. It highlights benefits, common risks such as device loss and downgrade attacks, and practical migration steps for enterprise deployment.
read more →

CISOs: Move Beyond Compliance to Anticipate Risk in 2026

🔒 CISOs entering 2026 should treat compliance as a baseline, not a destination. While frameworks like HIPAA, SOC 2 and ISO 27001 provide essential controls, relying solely on checklists breeds complacency and misses evolving threats such as AI-enabled attacks, third-party failures and future quantum risks. Adopt longer time horizons, scenario-based risk assessments and financial impact modelling to align security with business priorities and secure board support.
read more →

13 Questions to Vet IT Vendors and Reduce Third-Party Risk

🔐 As enterprises outsource more IT and adopt third-party SaaS, recent high-profile breaches show attackers are exploiting vendor trust pathways like help desks, OAuth tokens, and permissive integrations. CSOs should treat vendor selection as continuous risk management and demand strong attestations (e.g., SOC 2 Type II, ISO/IEC 27001), inventories of OAuth/API relationships, and evidence of actual workflow execution. The article lists 13 targeted questions covering controls, notification commitments, testing cadence, isolation measures, and insurance to reduce supply-chain risk.
read more →

AWS Landing Zone Accelerator: Universal Configuration

🔒 AWS has released the Landing Zone Accelerator on AWS sample security baseline called the Universal Configuration, designed to deploy a secure, multi-account environment rapidly. It encodes AWS Well‑Architected security best practices and automates hundreds of controls to accelerate compliance for regulated workloads. The release is paired with the LZA Compliance Workbook on AWS Artifact, which maps technical controls to frameworks such as NIST, ISO, HIPAA, and CMMC.
read more →

Why ISO and ISMS Certifications Fail: Nine Common Pitfalls

🔒 Implementation and certification of ISO standards or an ISMS frequently falter due to avoidable organizational and technical mistakes. The article outlines nine recurring issues — from weak management sponsorship and treating certification as a one‑off task to poor employee engagement, inadequate skills development, dishonest assessments, and insufficient follow‑up. For each pitfall it recommends practical remedies such as executive commitment, clear planning, targeted training, honest risk analysis, automation where appropriate, and adequate resourcing to make the management system functional and sustainable.
read more →

Why ISO/ISMS Security Certifications Often Fail and How

🛡️ Many ISO and ISMS certification efforts falter not because the standards are unclear but because organisations treat certification as a one-off checkbox activity rather than embedding controls into daily operations. Common failures include weak senior leadership commitment, insufficient employee involvement and training, wishful thinking about risks, and underinvestment in proper implementation. Practical remedies include clear planning, honest risk assessment, executive sponsorship, targeted competency building, and treating the ISMS as a continuous process rather than a closed project.
read more →

Rethinking Service Provider Risk: A CISO Imperative

🔍 As organizations outsource more critical systems and security functions to managed service providers, the complexity and frequency of third-party incidents are rising — 47% of organizations reported a third-party breach in the 12 months to mid-2025. Security leaders must balance rigorous, standards-based assurance (for example ISO 27001 or SOC 2) with relationship-driven vetting that fosters transparency and shared responsibility. Experts from media company Advance, the University of Queensland and vendor advisors argue that questionnaires alone are insufficient: meaningful dialogue, selective disclosure (summaries of pen tests rather than full reports), contractual clarity, and AI-aware controls are all needed to assess and manage evolving risks.
read more →

Six IT Risk-Assessment Frameworks for Enterprise Governance

🛡️ This article summarizes six prominent IT risk-assessment frameworks—COBIT, FAIR, ISO/IEC 27001, NIST RMF, OCTAVE and TARA—and explains their core purpose and methods. It contrasts governance-oriented, standards-based, lifecycle and threat-centric approaches and highlights where quantitative analysis or certification focus applies. The overview helps security and IT leaders identify which model or combination of models best fits organizational needs.
read more →

Aligning Security Architecture with Cyber Risk Governance

🔐 The author contends that cyber risk failures are often architectural and cultural, not purely technological, and argues for an ongoing cyber risk management process integrated with information security governance. He outlines a practical, strategic recipe—stakeholder mapping, framework selection (e.g., NIST CSF, ISO 27001), KPIs/KRIs, asset and threat assessments, and guardrails for cloud and generative AI workloads. The piece stresses building a mature risk culture, aligning GRC with the CISO role, enforcing technical controls and secure development practices (SAST/DAST/SCA), and running tabletop exercises to improve resilience and compliance with laws such as GDPR, CCPA and LGPD.
read more →

AWS Expands ISO and CSA STAR Scope with Two Services

🔒 Amazon Web Services (AWS) announced that EY CertifyPoint completed an onboarding audit and reissued ISO and CSA STAR certificates on August 13, 2025, with no findings. The audit expanded the certified scope to include AWS Resource Explorer and AWS Security Incident Response alongside the other services covered under multiple ISO standards and CSA STAR CCM v4.0. Customers can retrieve certificates through AWS Artifact and view the full certified service list on the AWS ISO and CSA STAR Certified page.
read more →

How Leading CISOs Secure Budget by Framing Business Risk

🔒 Security leaders are entering budget season facing skepticism; success now requires translating technical needs into clear business impact. Presentations that tie investments to revenue protection, uptime, regulatory compliance, and quantified loss avoidance resonate with boards. Adopt a risk-focused framework, define measurable KPIs such as time to detect and remediate, and employ continuous validation to expose exploitable weaknesses and track remediation velocity. Use standards like ISO 27001 and NIST as familiar anchors while showing real-world validation to avoid shelfware.
read more →