ISO 27001 Controls

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14

Availability is not achieved by hope. It is achieved by designing systems that continue to operate when something fails. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses suffer catastrophic downtime because they assumed their systems were redundant simply because they were in

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14 Read More »

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18

Utility programs are powerful by design. That power is exactly why they need tighter control than ordinary software. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations leave administrative utilities, system diagnostics, and low-level disk tools sitting openly on production servers for “convenience.”

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18 Read More »

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19

Most serious production outages do not start with clever external attackers. They start with uncontrolled software changes inside live environments. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses let well-meaning engineers or staff apply “quick updates,” unapproved utilities, or untested patches directly

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19 Read More »

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27

Most security failures are not caused by missing security tools. They are caused by poor design decisions made early and never revisited. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses bolt expensive security appliances onto a fundamentally flawed network design, only for

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27 Read More »

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29

Most security failures are discovered after deployment, when fixing them is slow, expensive, and disruptive. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations run comprehensive tests on software functionality, only to go live with massive security holes because no one bothered to

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29 Read More »

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31

Many major security incidents are not complex, external cyber attacks. They are simple, accidental changes made in the wrong environment. Over my 30 years in governance, risk, and compliance, I have seen developers accidentally drop a database or release unverified code simply because they thought they were connected to a

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31 Read More »

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34

Audits are supposed to reduce risk. Handled badly, they create it. Over my 30 years in governance, risk, and compliance, I have seen plenty of well-meaning auditors accidentally cause system outages or extract sensitive data without proper controls. Uncontrolled audit testing is a security incident waiting to happen. ISO 27001:2022

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34 Read More »