article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

If using an ISO audit software tool to achieve ISO certification is on your compliance roadmap, here’s a quick primer to get you up to speed and jumpstart your ISO compliance efforts. The ISMS provides tools for management to make decisions, exercise control, and audit the effectiveness of InfoSec efforts within the company.

Audit 52
article thumbnail

Driving Scientific Discovery with Big Data

Pure Storage

Created in 2013, the department is a leading light in exploring how healthcare is delivered in the UK and around the world. Given the scope and scale of the health information NDPH handles, data protection is vital for governance and auditing. That’s just one example of the critical health research NDPH conducts.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

7 mistakes that ISO 27001 auditors make

IT Governance BC

A good auditor will use the checklist as a summary at the beginning or end of their audit, with a more detailed assessment in their report, or they’ll use a non-binary system that doesn’t restrict them to stating that a requirement either has or hasn’t been met. They allow cost-cutting to starve the audit. Good auditing practices.

Audit 64
article thumbnail

5 Real-life business continuity planning cases you need to know

Online Computers

Just two months prior to the attack, an audit found almost 2,000 vulnerabilities in the City of Atlanta’s IT system, the majority of which stemmed from obsolete software and an IT culture of ad hoc processes. The 2013 lightning strike that razed a South Carolina MSP.

article thumbnail

Third-Party Risk Management 101

Fusion Risk Management

The basics of the contractual expectations should be documented in the policy and program, determining standard language over such items as the protection of data, the rights and obligations of both parties, and the ongoing expectations of supplying key information or allowing other items such as the right to audit the third party.

article thumbnail

IRM, ERM, and GRC: Is There a Difference?

Reciprocity

COSO’s ERM framework builds upon, and is intended to work with, the committee’s internal control framework issued in 1992 and updated in 2013. 2007-2012): Audit management, enterprise, and operational risk management, compliance beyond financial controls, and more. GRC 4.0: (2018-present): Automated GRC.

article thumbnail

Sustainability Reporting Accelerator

Advancing Analytics

Since 1 October 2013 the Companies Act 2006 (Strategic Report and Directors’ Report) Regulations 2013 have required all UK quoted companies to report on greenhouse gas emissions as part of their annual Directors' Report.

Travel 52