
technologyAug 26, 202121:55pending
What People Get Wrong About ISO 27001 Compliance
About this episode
Just because ISO 27001 suggests a control, doesn’t mean you have to have it – in fact, you could be hurting yourself if you do by wasting money and have more trouble in an audit than you would otherwise.
Your controls depend on your risk — not ISO suggestions.
That’s just one of the many misunderstandings people have about the ISO 27001 standard.
In this solo episode, host John Verry, CISO & Managing Partner at Pivot Point Security goes in depth on the most common misperceptions around ISO 27001 compliance.
Some notable examples: - Why your controls need to be in accordance with your risk - Why you don’t need to go crazy documenting absolutely everything - Why you shouldn’t overcommit on controls
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Your controls depend on your risk — not ISO suggestions.
That’s just one of the many misunderstandings people have about the ISO 27001 standard.
In this solo episode, host John Verry, CISO & Managing Partner at Pivot Point Security goes in depth on the most common misperceptions around ISO 27001 compliance.
Some notable examples: - Why your controls need to be in accordance with your risk - Why you don’t need to go crazy documenting absolutely everything - Why you shouldn’t overcommit on controls
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Get every episode summarized
Each time The Virtual CISO Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Virtual CISO Podcast

Episode 157: AI Security: Testing, Exploits, and Threat Feeds With Marco Figuero...
The Virtual CISO Podcast
Apr 3, 202650:13failed

Episode 156: AI Security: Threat Modeling & Pipeline Evolution with Jason Rebhol...
The Virtual CISO Podcast
Feb 25, 202648:52pending

Episode 155: Incident Response Testing in Cloud Forward Organizations with Matt...
The Virtual CISO Podcast
Dec 17, 202530:16pending

Ep 154: How DORA Will Impact US Companies with Dejan Kosutic
The Virtual CISO Podcast
Nov 6, 202533:56pending