● SYSTEM ONLINE Wednesday August 19, 2026 00:00:00.00
// LOG INTERCEPT: "Is social media really a platform to deliver your message to your audience? I hope..."// LOG INTERCEPT: "I was shocked when I heard from a “security professional” that using dark web as..."// LOG INTERCEPT: "Whitelisting has been for sure a relatively standard and sometimes as a hardening security measure..."// LOG INTERCEPT: "New European Union General Data Protection Regulation affects most US businesses"// LOG INTERCEPT: "I have talked many times about management and why I believe a manager cannot be..."

Category: Information Security Management System

2021.02.12 ID: 458

what is information security management?

information security management is almost similar to every other thing that is Subject to Management, or requires management, and I am not going to explain why we need a management function in a system to make sure system is running and functioning as expected, at least not in this article. by similarity, I mean there […]

[ READ TRANSMISSION → ]
2021.01.03 ID: 435

having something vs doing something

There is a difference between knowing the path and walking the path, right? just because I have something, does not mean I know something, or I do something. just because there are technologies, software or tools for a thing, let’s say GDPR compliance metrics, patch management, ITIL platforms, vulnerability scanning, application security testing…and so on, […]

[ READ TRANSMISSION → ]
2019.06.05 ID: 340

Vendor Risk Assessment: Hassle or Blessing?!

A Security Questionnaire, RFI, VRA (Vendor Risk Assessment), VR Management…helps customers identify and evaluate the risks of using a vendor’s product or service. Performing such a review is sometimes mandatory based on the industry (e.g. healthcare). During this standard business process, customer collects written information about security capabilities of a supplier and you could barely […]

[ READ TRANSMISSION → ]
2019.02.14 ID: 55

Security Program: How To Thrive?

From struggling or hardly surviving, to a fully supervised and manageable security program… Most companies are struggling with running an smooth security program. No matter how much they are spending on that, the difference is really not that much. From zero budget to million dollars security budgets, they still do not have enough trust in […]

[ READ TRANSMISSION → ]
2016.02.06 ID: 330

How to effectively audit any ISO 27001 process?

First of all, auditor needs to be a SME, not only to the security management system, but also specifically in regards to ISO 27001. The reason is related to the fact that “terminology” or “particular definition” of terms is important.  Then there are three simple aspects of any process or policy document which should have been adequately addressed by […]

[ READ TRANSMISSION → ]
2016.01.14 ID: 281

ISO 27001 Audit Tips and Tricks

the easy way to maintain an effective, low cost and smart ISO 27001 security management system Even though there is no magic behind auditing a system based on ISO 27001, there are simple tricks which help you handle ISO 27001 or many other similar standards and frameworks, both as and auditor and auditee. I would […]

[ READ TRANSMISSION → ]