Three acts, three different things to protect, and one approach they all take.
In this post we look at what NIS2, DORA and the CRA ask for,
and how a well-established ISMS can help us satisfy their requirements.
Random thoughts
Content
Latest
No one likes being exposed to danger, but avoiding all risk is impossible.
In this post we go through some concepts that should make the life of those
involved in handling risk easier. Risk ownership, appetite, tolerance, and more.
Determining the internal and external issues of the organisation
is the very first step in designing and implementing an ISMS.
In this post we provide an overview of popular methods,
and a concrete example of extracting security-relevant context from them.
Among the first decisions a risk practitioner faces is whether to express risk
quantitatively or qualitatively. We consider this framing a red herring.
The meaningful distinction is not between methods,
but between outcomes.
Every organisation has its own reasons for protecting information,
shaped by what it does, who it serves, and what it is trying to achieve.
In this post we look at why information security matters now more than ever.
Most of us understand risk as something ominous:
a danger, a threat, something that could go wrong.
Yet we celebrate risk-taking as bravery.
If we are rational beings, however,
how can we hold both of these conflicting beliefs simultaneously?