Posts

Book review: Permanent Record by Ed Snowden

Image
Title: Permanent Record Author: Edward Snowden ISBN: 978-1-250-23723-1 Price: US$18 from Amazon GH rating: 90% Summary Until I read this book, I considered my personal integrity a fundamental strength, core to my very being. It pales in comparison to Ed's extreme courage and intense determination to expose the shocking truth about the NSA's mass surveillance programme and the way it was concealed from Congress.

45 ISO Management Systems Standards

Image
The ISO website  currently lists 45 published M anagement S ystems S tandards: 1. ISO 7101:2023 Healthcare organization management — Management systems for quality in healthcare organizations — Requirements 2. ISO 9001:2015 Quality management systems — Requirements 3. ISO 10012:2003 Measurement management systems — Requirements for measurement processes and measuring equipment 4. ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes 5. ISO 14001:2015 Environmental management systems — Requirements with guidance for use 6. ISO 14298:2021 Graphic technology — Management of security printing processes

Book review: Thinking Fast and Slow

Image
Title: Thinking, Fast and Slow Author:  Daniel Kahneman ISBN: 978-0-374-53355-7 Price: $18 from Amazon GH rating: 60% Summary Didn't match up to the high expectations, for me. Wading through numerous examples with tedious explanations of subtle choices presented to experimental subjects made it a slog.

Systematically improving professional services

Image
My beady eye has been caught by another excellent thought-provoking Protiviti article by Jim DeLoach with Randy Armknecht concerning board-level blind spots. I highly recommend reading and contemplating Are There Blind Spots in Your Boardroom ? Jim and Randy offered ten practical suggestions for boards to address the issue. Here they are with my thoughts and ideas on how to apply them in other contexts, besides the boardroom, such as within the information risk and security management team for example: Assess whether current board culture, composition and agendas are fit for purpose in the current disruptive business environment. Assess the current team culture, composition, priorities, skills & competences, expertise, relationships, interests etc. with a view towards the future. How should the team evolve or adapt to changing circumstances, building on past successes and learning from failures?

Measuring and managing ethics

Image
KPMG's Soft Controls model caught my beady eye this week: KPMG are evidently using these 8 factors to analyse, measure and help clients manage their corporate cultures, claiming that "Our model gives organisations a valid tool for getting a clear picture of the current organisational situation, confront it, and break through the silence and passivity." Hmmm, 'silence and passivity', really KPMG? Well OK, whatever. It appears to be a viable approach.

An evolutionary revolution?

Image
"Mitigation and adaptation are required together to reduce the risks and impacts of climate change, including extreme weather events. Mitigation refers to actions taken to limit the amount of greenhouse gas emissions, reducing the amount of future climate change. Adaptation refers to actions taken to limit the impacts of a changing climate. Mitigation and adaptation together provide co-benefits for other environmental and social goals." That paragraph by Lizzie Fuller, Climate Science Communicator for the UK's Met Office, plucked from another excellent digest of lessons learned from various UK resilience exercises and initiatives , obviously con cerns climate change ... but it occurs to me that 'mitigate and adapt' might be a novel approach to information risks and impacts as well.

Pragmatic ISMS implementation guide (FREE!)

Image
Early this morning ( very  early!) I remotely attended an ISO/IEC JTC 1/SC 27/WG 1 editing meeting in London discussing the planned revision of ISO/IEC 27003:2017 . Overall, the meeting was very productive in that we got through a  long  list of expert comments on the preliminary draft standard, debated the objectives of the project and the standard and reached consensus on most points. In summary: 27003 is to be revised to align with the current 2022 releases of ISO/IEC 27001 , 27002 and 27005 : These changes are  mostly  minor aside from the new section 6.3 on ISMS changes.