Managing security
NIS2, DORA and the CRA: three legal acts, one approach
Three acts, three different things to protect, and one approach they all take. In this post we look at what NIS2, DORA and the CRA ask for, and how a well-established ISMS can help us satisfy their requirements.
Understanding the environment our ISMS lives in
Determining the internal and external issues of the organisation is the very first step in designing and implementing an ISMS. In this post we provide an overview of popular methods, and a concrete example of extracting security-relevant context from them.
What is information security, and why does it matter?
Every organisation has its own reasons for protecting information, shaped by what it does, who it serves, and what it is trying to achieve. In this post we look at why information security matters now more than ever.