photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

245
active users

#isms

0 posts0 participants0 posts today
Continued thread

ISO 27000 nit #3. I had to stare at this for several minutes to try to figure out what "enhancing societal values" was doing in this list. IMO the meaning of all the other list items it clear, but that one's clear as mud. I _think_ what they're trying to get at is improving the security culture within the organization being managed, but honestly, that's just a guess, I'm not even certain that's what they mean.
#infosec #compliance #ISO #ISO27000 #standards #isms

Continued thread

ISO 27000 nit #2: The definition of "risk" provided here, "effect of uncertainty on objectives," is dumb, obscure, unhelpful, bureaucratic gobbledygook. It in no way resembles the dictionary definition of risk, which much more closely approximates what I think of when I use the word risk or see it used in an information security concept. I am challenged to understand why they chose this nonsense definition and what they hope to achieve by it.
#infosec #compliance #ISO #ISO27000 #standards #isms

I am reviewing ISO 27000, as one does for shits and giggles, and I am curious about the motivation behind making "interested party" the preferred term while "stakeholder" is allowed but not preferred.
In the contexts in which I see stakeholder used, I believe it is a more accurate term than "interested party." Preferring the latter term IMO obfuscates meaning rather than clarifying it.
#infosec #compliance #ISO #ISO27000 #standards #isms

📣 New #infosec #job #offer: EGI Foundation is looking for a new Information Security Manger to manage an ISO/IEC 27001 certified #isms covering services to support the EGI infrastructure and community!

Work fully #remote or from #Amsterdam in collaboration with an internationally distributed team of great people.

It's currently my job, but I'm moving to new adventures, so feel free to DM me if you have questions.

#openresearch #openscience #security

egi.eu/article/job-information

EGIJob: Information Security ManagerEGI is looking for an Information Security Manager. Apply today! The deadline for applications is 10 April 2025

Wenn #KI die Lösung sein soll für nicht vorhandenes #ISMS und #BCMS und keine Regulatorik durch (#NIS2-)Gesetze bestehen:

Bundesregierung erwägt den Einsatz von KI zur Cyberabwehr

"#Bundesbehörden waren im vergangenen Jahr von 80 „IT-Sicherheitsvorfällen“ betroffen. Davon waren 17 und damit etwas mehr als 20 % erfolgreich."
handelsblatt.com/politik/deuts

www.handelsblatt.comHandelsblatt
Replied in thread

@jos1264 Well... Icm more "classic", authenticity is a subset of integrity in my eyes. And non-repudiation is a thing following directly out of confidentiality (of the password) and integrity (of the systems)... ok, and to be fair: out of logging things, so...

yeah. This article might have shaken the foundation of my arguments while writing this toot. Thanks.

Das Bundesamt für Sicherheit in der Informationstechnik (BSI) macht den IT #Grundschutz und damit den Stand der Technik maschinenlesbar!

"Der neue IT-Grundschutz wird vollständig prozessorientiert aufgebaut und basiert auf einem digitalen Regelwerk in Form einer #JSON Datei."

#SdT #ISMS #BCM
bsi.bund.de/DE/Themen/Unterneh

Bundesamt für Sicherheit in der InformationstechnikIT-Grundschutz

𝗦𝘁𝗮𝘁𝘂𝘀-𝗨𝗽𝗱𝗮𝘁𝗲 𝘇𝘂𝗿 𝗱𝗲𝘂𝘁𝘀𝗰𝗵𝗲𝗻 𝗨𝗺𝘀𝗲𝘁𝘇𝘂𝗻𝗴 𝘃𝗼𝗻 𝗡𝗜𝗦𝟮: 𝗩𝗼𝗿𝘁𝗿𝗮𝗴 𝘃𝗼𝗻 𝗠𝗮𝗻𝘂𝗲𝗹 𝗔𝘁𝘂𝗴 𝗮𝘂𝗳 𝗬𝗼𝘂𝗧𝘂𝗯𝗲 🎞️

@HonkHase gab als Speaker beim Event von „Security unter Kontrolle“ ein aktuelles Status-Update zur deutschen Umsetzung von #NIS2

Er teilte seinen „Blick in den Maschinenraum“: Wo stehen wir, was sind besonders herausfordernde Anforderungen, was wird heiß diskutiert – und warum dauert das eigentlich alles so lange?

Zum Vortrags-Video: ▶️ youtube.com/watch?v=XUES3PgGm5

Wenn ihr nach zertifizierten Unternehmen Ausschau haltet, dann auch immer auf irgendwelchen Unternemenssites oder in Broschüren auf eine kleine Formulierung achten. 
Es ist ein Unterschied wenn es heißt „ISO xxxxxx zertifiziert“ oder „nach ISO xxxxxx“ zertifiziert. #isms

Continued thread

#Introduction cont.: The things that fascinate me are simply too vast to list, but I've spent a great deal of my #disability downtime studying #totalism (est. 2012), an umbrella term I use to explore #historical and contemporary #authoritarian structures, states, groups, and personalities, as well as all of the #isms they create as a toxic framework from which to build. Most of my field research has been on social media platforms. >>

#introduction

#hello people. Ståle from Norway. I've been doing tactical and strategic #infosec and #irt in #HigherED for the last seven years. It all started with a bunch of diskettes and c.o.l.a. in 1993, and since then I've worked as a sysadmin. Mostly unix-es, but also Windows. This includes project management, #monitoring, #architecture, designing an #operations center and touching a bunch of technologies over the years. I still code a little #shell and #python. Been using #cfengine and #tivoli with a smile.

A memorable moment still is opening 7 xterms and compiling X11R6 for #sunos #solaris #hp-ux #ultrix #irix #linux #digitalunix and managing the configuration and security of tons of servers and clients centrally. This must have been 2000 or so.

These days I tend to like logging and #siem frameworks like #elk, teaching users and management how to make smart choices, general config management and hardening, IAM-stuff and the essential symbiosis between #sysadmin stuff and infosec stuff. #isms. #policies. #architecture.

I also like #photography #lego #rpg #larp #cooking #politics #society #emacs #languages #puns. A lot nicer than the picture. He/Him.