Get short, timely messages from Dejan Kosutic.

Twitter is a rich source of instantly updated information. It's easy to stay updated on an incredibly wide variety of topics. Join today and follow @Dejan_Kosutic.

Get updates via SMS by texting follow Dejan_Kosutic to 40404 in the United States
Codes for other countries

Two-way (sending and receiving) short codes:
Country Code For customers of
Australia
  • 0198089488 Telstra
Canada
  • 21212 (any)
United Kingdom
  • 86444 Vodafone, Orange, 3, O2
Indonesia
  • 89887 AXIS, 3, Telkomsel
Ireland
  • 51210 O2
India
  • 53000 Bharti Airtel, Videocon
Jordan
  • 90903 Zain
New Zealand
  • 8987 Vodafone, Telecom NZ
United States
  • 40404 (any)

Dejan_Kosutic

  1. The biggest difference between ISO 22301 and BS 25999-2 is in management - setting objectives, measuring, compliance bit.ly/LD0OXd
  2. Out of 23 most important sections in ISO 22301, 5 are with significant changes to BS 25999, 8 with moderate and 10 with minor changes
  3. Companies already certified against BS 25999-2 will have to "upgrade" to ISO 22301 until May 2014 - see infographic bit.ly/LD0OXd
  4. ISO 22301 vs. BS 25999-2 - An Infographic bit.ly/K8tDGO
  5. ISO 22301 is published, but BS 25999-2 will still be valid until November 2012
  6. BCM should not be the responsibility of IT dept only because both the information and business processes need to be recovered #iso22301
  7. Disaster recovery is only a part of business continuity - having data without people and processes to use it doesn't make sense #iso22301
  8. Most of the companies implementing ISO 27001 choose between 110 and 130 controls to implement
  9. Main part of ISO 27001 (clauses 4 to 8) wouldn't make sense without 133 controls from Annex A - but the opposite is true also
  10. @el_wafa The selection of controls depends on the existence of risk - if there is no risk (or other requirement), then no control is needed
  11. @brianhonan I'm afraid such cases are too often...
  12. Not every control from ISO 27001 Annex A is mandatory! (a common mistake made by IT practitioners)
  13. Only 50% of controls from ISO 27001 Annex A are about IT - the rest are physical security, legal protection, HR mgt, organization, etc.
  14. @danbratt99 Thanks, Daniel - I agree completely!
  15. @stromsjo They're usually sceptical about both the objectives and (especially) implementation...
  16. The best way to deal with BCM sceptics is to do an exercise/testing - they will then realize why good planning is important
  17. Scepticism on whether the business continuity plans would work is probably #1 difficulty when implementing business continuity #bcm
  18. New blog post - Top 10 information security blogs bit.ly/J9T6PD
  19. Free webinar - ISO 27001 benefits: How to obtain management support ow.ly/aE2SC
  20. Implementing only #iso27002 results usually in wrong infosec perception - it's better to start with #iso27001 and use 27002 as guideline