Good morning everybody,
It is now official, I will be participating to the Iqnite Conference in Geneva on June 15th 2010. The Iqnite conference (formerly known as Software & Systems Quality Conference) is one of the most important events for the Testing and Quality community.
Over the course of the conference, industry professionals will share practical strategies and knowledge providing you with valuable information to raise the overall benefit of Testing and Quality Management in your organization and increase profits.
This year, a call for paper specific to Information Security topics was made and I am happy that my suggestion was accepted. I will conduct a 90-minute workshop on ISO:27001 implementation pitfalls and lessons learnt from the field.
I was also happy to learn that Mr. Stephan Slunitschek will participate in the conference and present the PCI-DSS Implementation Project we are currently working on at the Touring Club Swiss (TCS). Stephan is a member of the management consulting office at the TCS and he his the PCI-DSS Project Director on which I act has the Subject Matter Expert.
The presenters who comes from the Geneva and Vaud Canton, Cosworth, Merck, Generali, SQS, TCS, Above Security, Skyguide, Evocean, Capital Group and Six Group will be sharing their experience with regards to testing, quality and the business benefits derived from those initiatives.
To conclude, I personally think this conference will be interesting, since we will have among us people from different industry sectors (Government, Insurance, Pharma...) and holding a mix of different position (Trainers to CIO...) who will share real life experiences.
I hope some of you will be able to join us in beautiful Geneva on June 15th!
Martin Dion (CISSP/CISM)
ISO:27001/20000 Lead Auditor & Trainer
CTO @ Above Security
February 23, 2010
February 22, 2010
New Training : ISO 27001 Roles and Responsibilities
Good day !
I am happy to announce you the availability of this second training session which focus on information security roles and responsibilities.
This is a mini-training to keep you from starving until I publish the upcoming ISO:27001 Clause 4 training.
The duration is only 15 minutes but it touches two very important concepts, the Everett Rogers Innovation Adoption Curve Applied to Information Security Management:
And the ISO 27001 Wheel of Roles and Responsibilities:
To learn more about those two concepts, listen tho the training by clicking on the image !
I hope you will enjoy, thanks in advance for posting your comments!
Martin Dion (CISSP/CISM)
ISO:27001/20000 Lead Auditor & Trainer
CTO @ Above Security
I am happy to announce you the availability of this second training session which focus on information security roles and responsibilities.
This is a mini-training to keep you from starving until I publish the upcoming ISO:27001 Clause 4 training.
The duration is only 15 minutes but it touches two very important concepts, the Everett Rogers Innovation Adoption Curve Applied to Information Security Management:
And the ISO 27001 Wheel of Roles and Responsibilities:
To learn more about those two concepts, listen tho the training by clicking on the image !
ISO 27001 February Training
See more presentations by martin.dion |
I hope you will enjoy, thanks in advance for posting your comments!
Martin Dion (CISSP/CISM)
ISO:27001/20000 Lead Auditor & Trainer
CTO @ Above Security
Libellés :
A8. Human Resources Security,
ISO 27001,
Training Content
February 8, 2010
Social networks at work: To be or not to be?
Whether you like it or not, whether you use them or not, social networks are now part of our life, if not yours directly, it is for some of our friends, children and colleagues.
Now that we have them in our lives, we have to learn to use it safely and correctly, thus the question: Is it ok to have them and use them at work?
Now that we have them in our lives, we have to learn to use it safely and correctly, thus the question: Is it ok to have them and use them at work?
Before answering, let’s just step back a few years ago…
When the “Web/Internet” appeared in the corporate world, I recall most of my client saying there was no need for such a thing at work, it was a total waste of time, employees where losing productivity… To some extent it was true, but honestly, today, lots of people cannot perform their job without accessing it.
It is still true that there is some loss of productivity but it brings a lot of joy and relaxation to workers. Being able to coordinate some personal issues via email, find the next vacation spot online, reserve tickets without having to drive down to a travel office. Let’s be honest, it saves us a lot of time and it improved our quality of life, happiness, and therefore, improve our ability to perform job better because overall, personal things are now easier to manage.
It was a paradigm shift back then as the social networks are right now. The thing is that most of us just didn’t found yet the best way to leverage them for day to day business.
With that said, we can’t use them inconsiderately, especially not at work. Although you might not be able to establish the value of social networks for your business yet, you might still decide to “please” your staff and allow the access and use of social network in the office. If you do so, make sure you train your staff to limit potential and/or negative impacts on your business.
To help you do this, the ENISA (European Network and Information Security Agency) has conducted a study and produced a report (available for download here) that establish 17 golden rules social network users should follow to insure an adequate level of security and act responsibly when using them.
Although it makes a lot of sense to security professionals, I have noticed that a lot of people do not see the potential issues with social networks. In a nutshell, the ENISA suggest that the users:
- Pay attention to what they post and upload
- Choose friends with care- Protect the work environment and avoid reputational risks
- Protect mobile phones (lots of mobile users out there)
- Respect other people’s privacy
- Get trained, get an understanding of the risks
- Protect their privacy using adequate privacy settings
- Report lost/stolen mobile ASAP
- Pay attention to location based services
There is much more to it than those simple recommendation topics in the report. A lot of the information can be re-use and integrate into your own security awareness training so please take the time to read it carefully.
All in all,some of the real risks of social networks from a business standpoint are:
- Cyber bullying and electronic harassment between employees or between your staff and your competitors staff??? (come on, we are not 12 year old anymore);
- The principle of “guilty by association”: When people privately belong to group or associations that do not represent well your overall corporate culture, standpoint or image;
- Leakage of privileged information. It is human nature to speak about what we do. Sometime, people get excited about a specific project or initiative they work on and starts discussing it online. This happen all the time over email and bulletin board and that risk is even more important with social network since you have to feed the beast once your in; and,
- Potential loss of control over corporate image: It happen when employee start defending corporate point of view based on their own interpretation of events or when they publicly complain about something that should be managed internally.
To conclude, private and work lives are to be kept apart. If you are to allow people to use social networks at work, clear boundaries are to be established between those two. I think it is important to define posting guidelines (with example of what is allowed and what is not allowed) and make them available to your staff.
PS: Watch out for the staff who travels a lot, many social networks user implement mobile components on their cell phone and it can crank up a bill pretty quickly!
Thanks for reading and have a great day,
Martin Dion (CISSP/CISM)
ISO:27001/20000 Lead Auditor & Trainer
CTO @ Above Security
February 5, 2010
ISO 27003:2010 Standard Now Available
Good afternoon everybody,
Last post for this week :) In case some of you didn't noticed, the ISO 27003 standard version 2010 was published this week.
This standard focus on the key elements and deployment activities necessary to successfully design and implement an ISO 27001 based Information Security Management System (ISMS).
It describes the various steps that you need to go through to specify, design, define and implement the requirements of the ISMS from it's inception to a "certifiable" status and provides guidance on how to plan the ISMS project and get management endorsement.
In the next trainings we will go in more details on this standard content and why it might appeal to you if you are responsible for implementing an ISMS within your organisation. For those of you who ever heard of the BIP documents from the BSI, you must be aware that the objectives are the same and that they are both similar in nature.
The 2010 official release is shorter (68 pages) than the 2007 originally planned draft who accounted for no less than 110 pages but in this case, quality comes before quantity.
Every ISO practionners and consultants should have their own copy! Don't forget that this is copyrighted material, every member of the project team should also have it's named copy unless your company or the client have a site license! It can be purchased in electronic or paper form from the ISO web site at a cost of 168.- Swiss franc plus shipping if applicable.
Have a great week end !
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Last post for this week :) In case some of you didn't noticed, the ISO 27003 standard version 2010 was published this week.
This standard focus on the key elements and deployment activities necessary to successfully design and implement an ISO 27001 based Information Security Management System (ISMS).
It describes the various steps that you need to go through to specify, design, define and implement the requirements of the ISMS from it's inception to a "certifiable" status and provides guidance on how to plan the ISMS project and get management endorsement.
In the next trainings we will go in more details on this standard content and why it might appeal to you if you are responsible for implementing an ISMS within your organisation. For those of you who ever heard of the BIP documents from the BSI, you must be aware that the objectives are the same and that they are both similar in nature.
The 2010 official release is shorter (68 pages) than the 2007 originally planned draft who accounted for no less than 110 pages but in this case, quality comes before quantity.
Every ISO practionners and consultants should have their own copy! Don't forget that this is copyrighted material, every member of the project team should also have it's named copy unless your company or the client have a site license! It can be purchased in electronic or paper form from the ISO web site at a cost of 168.- Swiss franc plus shipping if applicable.
Have a great week end !
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
February 4, 2010
Privacy Protection – Swiss Made
Good morning,
Yesterday, I participated with 65 of my peers to an informational workshop on the “current state of affairs” with regards to the Privacy Protection laws and initiatives that are underway in Switzerland.
The “core” working group composed of the unit chief, the privacy commissioner and both legal councils exposed us over a two-hour period to various bits and pieces of information that I will try to resume in the current posting.
First, let me start by saying that although the Swiss regulation is not really aggressive in terms of retaliation against the privacy vandals and “neglector”, it is really well structured. Some might complain it is too much, but it is clear that all the relevant aspects are formally addressed in the regulation.
Currently, the mandate of this working group is to bring to the market a government approved way of certifying both product and services in terms of privacy protection compliance. This is quite unique for now since I am not aware of any formal “country driven” initiative. A lot of private and commercially driven privacy label exists but the Swiss government is attempting to formalize certification channels and to impose such exercise in the regulation.
This information session started with a presentation of the results from a survey that was conducted among the participants a few weeks before. The topic of the survey was service and product certification which is, in my understanding and opinion, important to determine if this vision corresponds to a market need and not only to a government wish. Roughly, over 75% of the response confirms a market demand which is great news for the core workgroup.
We were then presented with the current status with regards to legislative works, everything seems to be on track from that standpoint as well.
Then, Mr. Baumann, the Swiss Federal Privacy Commissioner (or Préposé Fédéral à la Protection des Donnée et à la Transparence) presented us his analysis of what is already available on the market in terms of service and product certification processes.
To resume, the Swiss government is currently looking at an ISO type of certification based on currently available standards such as ISO 27001 and ISO 20000 for service certification and ISO 15408 (Common Criteria) for product certification.
I personally agree with the approach. Simply said, there is no other way to go. Continuous improvement and independent certification of both service and product is necessary. Some elements still need to be cleared out: Which standards should be use, how to tackle the task and how does this fit in the more general framework / certification market?
To clear out those last questions, a workgroup involving the private sector is currently in the buildup. Work is scheduled to be started in March 2010 and deliverables are expected by mid-2011. My candidature is up, I will try to get involve in that workgroup for myself since I find this pretty interesting, but also on behalf of the CLUSIS.
To obtain further information on the regulation, I invite you to visit the commissionners' web site.
Have a great day and talk to you soon,
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Yesterday, I participated with 65 of my peers to an informational workshop on the “current state of affairs” with regards to the Privacy Protection laws and initiatives that are underway in Switzerland.
The “core” working group composed of the unit chief, the privacy commissioner and both legal councils exposed us over a two-hour period to various bits and pieces of information that I will try to resume in the current posting.
First, let me start by saying that although the Swiss regulation is not really aggressive in terms of retaliation against the privacy vandals and “neglector”, it is really well structured. Some might complain it is too much, but it is clear that all the relevant aspects are formally addressed in the regulation.
Currently, the mandate of this working group is to bring to the market a government approved way of certifying both product and services in terms of privacy protection compliance. This is quite unique for now since I am not aware of any formal “country driven” initiative. A lot of private and commercially driven privacy label exists but the Swiss government is attempting to formalize certification channels and to impose such exercise in the regulation.
This information session started with a presentation of the results from a survey that was conducted among the participants a few weeks before. The topic of the survey was service and product certification which is, in my understanding and opinion, important to determine if this vision corresponds to a market need and not only to a government wish. Roughly, over 75% of the response confirms a market demand which is great news for the core workgroup.
We were then presented with the current status with regards to legislative works, everything seems to be on track from that standpoint as well.
Then, Mr. Baumann, the Swiss Federal Privacy Commissioner (or Préposé Fédéral à la Protection des Donnée et à la Transparence) presented us his analysis of what is already available on the market in terms of service and product certification processes.
To resume, the Swiss government is currently looking at an ISO type of certification based on currently available standards such as ISO 27001 and ISO 20000 for service certification and ISO 15408 (Common Criteria) for product certification.
I personally agree with the approach. Simply said, there is no other way to go. Continuous improvement and independent certification of both service and product is necessary. Some elements still need to be cleared out: Which standards should be use, how to tackle the task and how does this fit in the more general framework / certification market?
To clear out those last questions, a workgroup involving the private sector is currently in the buildup. Work is scheduled to be started in March 2010 and deliverables are expected by mid-2011. My candidature is up, I will try to get involve in that workgroup for myself since I find this pretty interesting, but also on behalf of the CLUSIS.
To obtain further information on the regulation, I invite you to visit the commissionners' web site.
Have a great day and talk to you soon,
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
February 3, 2010
Business Continuity Management System – NFPA 1600 2010 released
Good day everybody!
Before diving into the subject, I just want to inform everybody that the next video training will be available toward the end of next week. Now, lets get back to business :)
For many years now, a lot of people had been struggling with business continuity. First and foremost, it is often a question of language: business continuity, disaster recovery, resiliency, service availability… People use different terms and do not necessarily agree on the scope and meaning of those words.
With that said, whatever it means to you, from an ISO 27001 or BS 25999 perspective they all fall within one category: Business Continuity Management.
The reason why I think it is important to talk about this today, is that the National Fire Protection Association of the United States had just updated the 2007 version of the standard for Disaster/Emergency Management & Business Continuity Programs. The standard can be downloaded for free, right here!
The purpose of my posting is not to provide you with details about the changes between both versions but rather to expose you to the existence of the standard and its content to help you gain a better understanding of Business Continuity Management Systems.
Chapter 3 – Definition
It provides the reader with 24 definitions of words we commonly use when discussing BCMs.
Chapter 4 – Program Management
This section defines the requirement in terms of management commitment, roles and responsibilities, resource allocation and records management. For those of you who are already versed in ISO:27001 and BS:25999, you can see there are a lot of “clause 4 to 8” elements in there.
Chapter 5 – Planning
Focus on establishing the scope, understanding the constraints and requirements, conducting risk and business impact assessment and making decision in terms of preventive measures and possible mitigations.
Chapter 6 – Implementation
Talks about the various elements that needs to be put in place to make it happen such has emergency response, incident management, training, crisis communication, emergency operation centers and the various operational procedures.
Chapter 7 – Testing and Exercises
Document the requirements for testing, exercising, evaluating and insuring that the plan actually works.
Chapter 8 – Program Improvement
Again, much like the PDCA enforced by ISO standards, the NFPA clearly states how and why the program should improve and what needs to be done to insure adequacy of the program with regulatory changes and the evolution of the organization.
Annex A – Explanatory Material
Provides 15 pages of really useful supplemental information such as a mapping of the NFPA 1600:2010 standards to the Disaster Recovery Institute Professional Practices and a bunch of guidelines for many of the topics mentioned previously.
Annex B – Program Development Resources
Includes a list of supplemental reference and resources on the subject.
Annex C – Conformity Self Assessment
This is really a great section in this document! It provides the reader with a list of self-audit/self-assessment questions to go through to establish if you are doing your job in terms of business continuity and with regards to the management of the BCM program.
All in all, this is a great and free resource to get a better understanding of BCM. In comparison to BS:25999, it lacks a bit in terms of structure, components and workflow specifics to management systems and continuous improvement but the quality and depth of the information included as well as the practical aspects covered in there makes it a unique document that complements BS:25999 and which surely fills a lot of empty spaces left within ISO:27001.
As a conclusion, I just want to remind you how great Annex C is, although the standard is free, many people I know would have paid just to get that section!
Have a great evening and thanks for your time and comments !
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
January 29, 2010
ISO27001 Lead Auditor Certification & Thank you !
Good morning folks,
I promise myself that I would not plug anything on my personnal blog but I have been asked by the readers a couple of time per week since I started my blog : when and where do my next face-to-face training will be?
With that said, I just want to give you all a big thank you! Thanks for reading, thanks for coming back, thanks for the cheer up and thanks for the questions.
To give you a better idea, over a thousand unique visitors came to read my blog in the last month and the average time spent on the site is about 3 minutes (enough time to read the postings). Over 70% of you came back to the blog at least 5 times in January and last week online training was viewed by 150 persons already :)
Again, thank you all and see you soon,
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
(ATHQWWCEPEQE)
I promise myself that I would not plug anything on my personnal blog but I have been asked by the readers a couple of time per week since I started my blog : when and where do my next face-to-face training will be?
*** Beginning of Plug***
The date is now known, if any of you want to attend, I will be giving an RABQSA ISO 27001 Lead Auditor Certification class in Montreal, Canada between March 15th and 19th 2010. You can contact our Montreal office or myself to get more details.***End of Plug***
With that said, I just want to give you all a big thank you! Thanks for reading, thanks for coming back, thanks for the cheer up and thanks for the questions.
To give you a better idea, over a thousand unique visitors came to read my blog in the last month and the average time spent on the site is about 3 minutes (enough time to read the postings). Over 70% of you came back to the blog at least 5 times in January and last week online training was viewed by 150 persons already :)
Again, thank you all and see you soon,
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
(ATHQWWCEPEQE)
January 28, 2010
Risk, Security & Compliance Job Descriptions
Hello everybody,
I just came across an interesting eBook created by Mr. George Lekatis from Compliance LLC . This eBook provides a collection of 100 job descriptions covering risk management, information security and compliance positions.
The descriptions are about 2 pages each and are more in the line of job posting, still they are interesting in my opinion to point you in the right direction. It can be freely downloaded here. There is a bit of self promotion in there but I can not blame him, the book is free and normalizing all job description surely took some time. If I had one recommandation to make to Mr. Lekatis, it would be to provide a better index to ease the navigation through the book.
As a final remark, if you are looking for a formal and more detailed resource on the subject of job description, roles and responsibilities, you should look at the all time classic “Information Security Roles & Responsibilities Made Easy V.2.0” by Cresson Wood. It might seem a bit pricy but it definitely worth the investment if you are looking for a full blown reference on the subject.
Talk you soon !
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
I just came across an interesting eBook created by Mr. George Lekatis from Compliance LLC . This eBook provides a collection of 100 job descriptions covering risk management, information security and compliance positions.
The descriptions are about 2 pages each and are more in the line of job posting, still they are interesting in my opinion to point you in the right direction. It can be freely downloaded here. There is a bit of self promotion in there but I can not blame him, the book is free and normalizing all job description surely took some time. If I had one recommandation to make to Mr. Lekatis, it would be to provide a better index to ease the navigation through the book.
As a final remark, if you are looking for a formal and more detailed resource on the subject of job description, roles and responsibilities, you should look at the all time classic “Information Security Roles & Responsibilities Made Easy V.2.0” by Cresson Wood. It might seem a bit pricy but it definitely worth the investment if you are looking for a full blown reference on the subject.
Talk you soon !
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
January 27, 2010
Subscription Service Now Available !
Good day!
As requested by many of you, I have set up an email subscription service to complement the Blog. Now it is up to you to become an official “Follower” or to simply subscribe to the posting notification mailing list using the widget on the left toolbar.
Subscription to the post notification service mailing list will enable you to receive a short email with a link to new posting as soon as they become available on my blog.
You can confidently use this feature knowing that it uses a double opt-in system and that your email won’t be made available to anybody else but me. This mailing list will only be use to inform you of new posts and major change to the blogging system.
I hope this new feature is in line with your expectations.
Have a great day!
PS: As a 3rd and final alternative, you can also send an email to martindionblog+subscribe@googlegroups.com
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Cloud Computing Security - 10 questions to ask yourself
In a recent CIO Magazine article, Tim Brown took the time to assemble 10 questions that should be investigated in detail before making the move the Cloud Computing.
Here is a brief recap on which I hope we’ll be able to brainstorm on them together:
1. Does Cloud Computing will change my risk profile?
2. Does it have an impact on my current information security policy, should it be modified in accordance?
3. Does cloud computing prevents us from meeting our regulatory obligation?
4. Is the selected provider is using / is certified on current security standards (ISO 27001, FINMA, FISMA…)?
5. What is the incident response workflow between them and our organization should an incident occur?
6. Who is responsible / liable for securing the data?
7. How do I ensure that only appropriate data is moved to the cloud?
8. How do I ensure that only authorized parties can access those data?
9. What is the hosting model and security architecture (clustering, zoning, isolation, segmentation, shared space…)?
10. How are we going to determine if we can trust this provider now and in the future?
The interesting thing about those questions is that they can be asked for any type of outsourcing deals.
My questions to you are:
- What are your top three questions in this list?
- What steps would you take to insure that you obtain adequate information to take a position on those three questions?
Have a great day and talk to you soon!
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Here is a brief recap on which I hope we’ll be able to brainstorm on them together:
1. Does Cloud Computing will change my risk profile?
2. Does it have an impact on my current information security policy, should it be modified in accordance?
3. Does cloud computing prevents us from meeting our regulatory obligation?
4. Is the selected provider is using / is certified on current security standards (ISO 27001, FINMA, FISMA…)?
5. What is the incident response workflow between them and our organization should an incident occur?
6. Who is responsible / liable for securing the data?
7. How do I ensure that only appropriate data is moved to the cloud?
8. How do I ensure that only authorized parties can access those data?
9. What is the hosting model and security architecture (clustering, zoning, isolation, segmentation, shared space…)?
10. How are we going to determine if we can trust this provider now and in the future?
The interesting thing about those questions is that they can be asked for any type of outsourcing deals.
My questions to you are:
- What are your top three questions in this list?
- What steps would you take to insure that you obtain adequate information to take a position on those three questions?
Have a great day and talk to you soon!
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Libellés :
A6.2. External Parties,
Cloud Computing Security,
General
January 21, 2010
First ISO:27001 training available - Introduction to standards
Good day !
I am happy to announce you the availability of this first training session which focus on the available standards in the market and provides you an overview of the ISO certification process.
This training as well as the ones to come will be available via AuthorStream. Click on the image to start the presentation!
I hope you will enjoy, thanks in advance for posting your comments!
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
I am happy to announce you the availability of this first training session which focus on the available standards in the market and provides you an overview of the ISO certification process.
This training as well as the ones to come will be available via AuthorStream. Click on the image to start the presentation!
ISO 27001 January Training
See more presentations by martin.dion |
I hope you will enjoy, thanks in advance for posting your comments!
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
January 18, 2010
Update and new risk certification (ISACA CRISC)
Good morning,
In case you wonder, I should be ready to post the first ISO training video this week. In the meantime, I came across a news piece and I thought it might be interesting to discuss it :)
As some of you may know, the ISACA is launching a new certification, the CRISC (pronounce See Risk). Like for previous certification, the ISACA will grandfather industry professional based on their existing credential to get certified (starting this April), or you will be able to take the exam in 2011.
Two things come to mind, if you are a risk management expert, get involved, I'll sure do, you can help the ISACA prepare the training or exam material over the course of 2010 so people can get trained and take the exam in 2011. If you are experienced enough to be grandfathered, it means you can help, so please do.
Now, the second thing that comes to mind is: Do we need another certification? The same question comes around every time a new one is launched. Already available on the market, there is the ISO 27005 Risk Management certification, the Associate Risk Manager (ARM), somebody will surely design something around ISO 31000 / ISO 31010, there is also the MoR certification for ITIL practitioners...
In my own opinion, the ISO27005 certification program is good but the standard is a bit weak, it is primarily design for supporting the ISO27001 company certification process and do not take in consideration the real operational risk management measure that organization is looking for, ISO31000 will surely complement well the 27005 standard to help people get a more holistic view of enterprise risks.
The ARM has been designed by the US insurance industry with a deep focus on estimation of risks and financing, it lack a lot in the area of information technology and business continuity risks while MOR is mostly (nearly only) about information technology, project management and business continuity...
So, by analyzing the market, I think we can safely assume that there is enough space (and differentiators) for a new certification. One must also take a step back to look at how the ISACA work. From my perspective, the biggest contribution of the ISACA is not the certification they launch but the body of knowledge they create to train and support professional on the core aspect of those certifications.
If you are certified, you already know what I am talking about, did you got rid of your CISA or CISM books? Surely not, they contain great information, I even know people that buy back the review manuals on a yearly basis to get up to date information.
Give me your thought and input on the subject, tell me what you think this certification and its body of knowledge should contain, we might be able to get something out of it, and I will escalate this information from the field to the association.
Have a great day and see you soon,
Martin Dion (CISSP/CISM)
ISO27001 Lead Auditor & Trainer
CTO @ Above Security
In case you wonder, I should be ready to post the first ISO training video this week. In the meantime, I came across a news piece and I thought it might be interesting to discuss it :)
As some of you may know, the ISACA is launching a new certification, the CRISC (pronounce See Risk). Like for previous certification, the ISACA will grandfather industry professional based on their existing credential to get certified (starting this April), or you will be able to take the exam in 2011.
Two things come to mind, if you are a risk management expert, get involved, I'll sure do, you can help the ISACA prepare the training or exam material over the course of 2010 so people can get trained and take the exam in 2011. If you are experienced enough to be grandfathered, it means you can help, so please do.
Now, the second thing that comes to mind is: Do we need another certification? The same question comes around every time a new one is launched. Already available on the market, there is the ISO 27005 Risk Management certification, the Associate Risk Manager (ARM), somebody will surely design something around ISO 31000 / ISO 31010, there is also the MoR certification for ITIL practitioners...
In my own opinion, the ISO27005 certification program is good but the standard is a bit weak, it is primarily design for supporting the ISO27001 company certification process and do not take in consideration the real operational risk management measure that organization is looking for, ISO31000 will surely complement well the 27005 standard to help people get a more holistic view of enterprise risks.
The ARM has been designed by the US insurance industry with a deep focus on estimation of risks and financing, it lack a lot in the area of information technology and business continuity risks while MOR is mostly (nearly only) about information technology, project management and business continuity...
So, by analyzing the market, I think we can safely assume that there is enough space (and differentiators) for a new certification. One must also take a step back to look at how the ISACA work. From my perspective, the biggest contribution of the ISACA is not the certification they launch but the body of knowledge they create to train and support professional on the core aspect of those certifications.
If you are certified, you already know what I am talking about, did you got rid of your CISA or CISM books? Surely not, they contain great information, I even know people that buy back the review manuals on a yearly basis to get up to date information.
Give me your thought and input on the subject, tell me what you think this certification and its body of knowledge should contain, we might be able to get something out of it, and I will escalate this information from the field to the association.
Have a great day and see you soon,
Martin Dion (CISSP/CISM)
ISO27001 Lead Auditor & Trainer
CTO @ Above Security
Libellés :
4.2.1. Establish the ISMS,
Risk Management,
Training Content
December 31, 2009
New look for 2010?
Good morning folks,
I hope you are doing well, there is only a few hours left before we move to 2010 so let me wish you and your family a happy new year full of health and fun :)
Based on the recommendations of a few followers, I have decided to personalize my blog to provide you with a better reading experience. I will stick to a simple style and limit as much as possible the use of gadgets.
I hope you will enjoy the changes!
Cheers,
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
I hope you are doing well, there is only a few hours left before we move to 2010 so let me wish you and your family a happy new year full of health and fun :)
Based on the recommendations of a few followers, I have decided to personalize my blog to provide you with a better reading experience. I will stick to a simple style and limit as much as possible the use of gadgets.
I hope you will enjoy the changes!
Cheers,
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
December 25, 2009
Editorial Calendar
Starting Q1-2010, I will try to publish at least two training sessions per month. I am planning to deliver 30 to 60 minutes capsules based on the following monthly editorial calendar:
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
- ISO family of standards, why use a standardized framework, the ISO:27001 standard and structure, the certification process
- ISO:27001 Clause 4 – ISMS requirements overview, defining the scope, document & record management, minimal documentation requirements
- Defining roles and responsibilities, planning the ISMS implementation project
- Risk management, risk analysis and the statement of applicability (SOA)
- ISO:27001 Clause 5 – Management responsibilities, sample ISO:27001 management awareness training
- ISO:27001 Clause 6 – Internal audits, building an internal audit program
- ISO:27001 Clause 7 – Management reviews, sample agenda
- ISO:27001 Clause 8 – Continuous improvement, root cause analysis, corrective & preventive action plans
- Annex A control objectives (A.5 to A.10)
- Annex A control objectives (A.11 to A.15)
- Other useful standards to ISMS implementation and business improvement, ISO20000/BS25999/PCI-DSS/ISO9001 overview
- Integrating and unifying multiple management systems to prevent redundancy and improve efficiency
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Launching my Blog
Good day all,
My name is Martin Dion, I am an information security professional located in Switzerland with over 15 years of experience specializing in ISO:27001, PCI-DSS and governance initiatives.
I am the co-founder and Chief Technology Officer at Above Security, an information security management consulting firm with head office in Canada serving customers in over 22 countries.
I hold various certifications such has CISSP, CISM, ISO:27001 Lead Auditor/Implementer & Trainer (RABQSA) and also ISO:20000 Lead Auditor.
Over the past few years, most of my engagements focused on helping clients implementing ISMS (information security management system) and teaching formal 27001 lead auditor and implementation classes.
I am currently writing a book on the subject and decided to create a series of training video capsules and a blog within which I will publish the relevant links and supporting papers.
Thanks in advance for your time and comments and I hope you will enjoy over the next twelve months the posting and training capsules.
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
Subscribe to:
Posts (Atom)

