Framework - ISO 27001 (Cyber)

By Jason Edwards

Listen to a podcast, please open Podcast Republic app. Available on Google Play Store and Apple App Store.

Image by Jason Edwards

Category: Courses

Open in Apple Podcasts


Open RSS feed


Open Website


Rate for this podcast

Subscribers: 1
Reviews: 0
Episodes: 71

Description

The ISO/IEC 27001 Framework is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It provides a systematic approach to managing sensitive information through risk management, governance, and control implementation. At its core, ISO 27001 helps organizations protect the confidentiality, integrity, and availability of data—whether stored, processed, or transmitted—by aligning security practices with business objectives and regulatory requirements. The framework is built around a risk-based process, requiring organizations to identify potential threats, assess their likelihood and impact, and implement appropriate controls from the companion standard ISO/IEC 27002. These controls cover a wide range of areas including asset management, access control, cryptography, operations security, and supplier relationships. By tailoring these controls to organizational needs, ISO 27001 supports both flexibility and accountability—ensuring that security measures are not just technical but also strategic and operational. Beyond compliance, ISO 27001 fosters a culture of continuous improvement through regular audits, performance monitoring, and leadership involvement. Certification to the standard demonstrates to customers, partners, and regulators that an organization follows internationally accepted best practices for managing information security risk. More than a checklist, ISO 27001 functions as an ongoing management framework that integrates security into every level of organizational decision-making, helping build trust, resilience, and long-term operational stability.

Episode Date
Welcome to Framework - ISO 27001
Oct 14, 2025
Episode 70 — A.8.33–8.34 — Test information; Protecting systems during audit testing
Oct 14, 2025
Episode 69 — A.8.31–8.32 — Separation of dev/test/prod; Change management
Oct 14, 2025
Episode 68 — A.8.29–8.30 — Security testing in development & acceptance; Outsourced development
Oct 14, 2025
Episode 67 — A.8.27–8.28 — Secure system architecture & engineering; Secure coding
Oct 14, 2025
Episode 66 — A.8.25–8.26 — Secure development lifecycle; Application security requirements
Oct 14, 2025
Episode 65 — A.8.23–8.24 — Web filtering; Use of cryptography
Oct 14, 2025
Episode 64 — A.8.21–8.22 — Security of network services; Segregation of networks
Oct 14, 2025
Episode 63 — A.8.19–8.20 — Software installation on operational systems; Network security
Oct 14, 2025
Episode 62 — A.8.17–8.18 — Clock synchronization; Privileged utility programs
Oct 14, 2025
Episode 61 — A.8.15–8.16 — Logging; Monitoring activities
Oct 14, 2025
Episode 60 — A.8.13–8.14 — Information backup; Redundancy of processing facilities
Oct 14, 2025
Episode 59 — A.8.11–8.12 — Data masking; Data leakage prevention
Oct 14, 2025
Episode 58 — A.8.9–8.10 — Configuration management; Information deletion
Oct 14, 2025
Episode 57 — A.8.7–8.8 — Anti-malware; Technical vulnerability management
Oct 14, 2025
Episode 56 — A.8.5–8.6 — Secure authentication; Capacity management
Oct 14, 2025
Episode 55 — A.8.3–8.4 — Information access restriction; Access to source code
Oct 14, 2025
Episode 54 — A.8.1–8.2 — User endpoint devices; Privileged access rights
Oct 14, 2025
Episode 53 — A.7.13–7.14 — Equipment maintenance; Secure disposal/re-use
Oct 14, 2025
Episode 52 — A.7.11–7.12 — Supporting utilities; Cabling security
Oct 14, 2025
Episode 51 — A.7.9–7.10 — Off-premises assets; Storage media
Oct 14, 2025
Episode 50 — A.7.7–7.8 — Clear desk/screen; Equipment siting & protection
Oct 14, 2025
Episode 49 — A.7.5–7.6 — Environmental threats; Working in secure areas
Oct 14, 2025
Episode 48 — A.7.3–7.4 — Securing offices/rooms/facilities; Physical security monitoring
Oct 14, 2025
Episode 47 — A.7.1–7.2 — Perimeters; Physical entry
Oct 14, 2025
Episode 46 — A.6.7–6.8 — Remote working; Event reporting
Oct 14, 2025
Episode 45 — A.6.5–6.6 — Responsibilities after termination/change; NDAs
Oct 14, 2025
Episode 44 — A.6.3–6.4 — Awareness, education & training; Disciplinary process
Oct 14, 2025
Episode 43 — A.6.1–6.2 — Screening; Terms & conditions of employment
Oct 14, 2025
Episode 42 — A.5 Integration Capstone — Pitfalls, auditor patterns, mappings
Oct 14, 2025
Episode 41 — A.5.37 — Documented operating procedures
Oct 14, 2025
Episode 40 — A.5.35–5.36 — Independent review; Compliance with policies/rules/standards
Oct 14, 2025
Episode 39 — A.5.33–5.34 — Protection of records; Privacy & PII protection
Oct 14, 2025
Episode 38 — A.5.31–5.32 — Legal/regulatory/contractual; Intellectual property rights
Oct 14, 2025
Episode 37 — A.5.29–5.30 — Security during disruption; ICT readiness for BC
Oct 14, 2025
Episode 36 — A.5.27–5.28 — Learning from incidents; Collection of evidence
Oct 14, 2025
Episode 35 — A.5.25–5.26 — Event assessment/decision; Incident response
Oct 14, 2025
Episode 34 — A.5.23–5.24 — Use of cloud services; Incident mgmt planning & prep
Oct 14, 2025
Episode 33 — A.5.21–5.22 — ICT supply chain; Monitoring/review of supplier services
Oct 14, 2025
Episode 32 — A.5.19–5.20 — Supplier relationships; Supplier agreements
Oct 14, 2025
Episode 31 — A.5.17–5.18 — Authentication information; Access rights
Oct 14, 2025
Episode 30 — A.5.15–5.16 — Access control; Identity management
Oct 14, 2025
Episode 29 — A.5.13–5.14 — Labelling of information; Information transfer
Oct 14, 2025
Episode 28 — A.5.11–5.12 — Return of assets; Classification of information
Oct 14, 2025
Episode 27 — A.5.9–5.10 — Asset inventory; Acceptable use
Oct 14, 2025
Episode 26 — A.5.7–5.8 — Threat intelligence; Security in project management
Oct 14, 2025
Episode 25 — A.5.5–5.6 — Contact with authorities; Special interest groups
Oct 14, 2025
Episode 24 — A.5.3–5.4 — Segregation of duties; Management responsibilities
Oct 14, 2025
Episode 23 — A.5.1–5.2 — Policies for InfoSec; Roles & responsibilities
Oct 14, 2025
Episode 22 — Clause 9.3 + 10 — Management review; Nonconformity; Continual improvement
Oct 14, 2025
Episode 21 — Clause 9.2 — Internal audit
Oct 14, 2025
Episode 20 — Clause 9.1 — Monitoring, measurement, analysis & evaluation
Oct 14, 2025
Episode 19 — Clause 8.2 + 8.3 — Risk assessment & treatment in operations
Oct 14, 2025
Episode 18 — Clause 8.1 — Operational planning and control
Oct 14, 2025
Episode 17 — Clause 7.5 — Documented information
Oct 14, 2025
Episode 16 — Clause 7.3 + 7.4 — Awareness; Communication
Oct 14, 2025
Episode 15 — Clause 7.1 + 7.2 — Resources; Competence
Oct 14, 2025
Episode 14 — Clause 6.3 — Planning of changes
Oct 14, 2025
Episode 13 — Clause 6.2 — Objectives & planning to achieve them
Oct 14, 2025
Episode 12 — Clause 6.1.3 — Risk treatment planning
Oct 14, 2025
Episode 11 — Clause 6.1.2 — Risk assessment methodology
Oct 14, 2025
Episode 10 — Clause 6.1 — Actions to address risks & opportunities
Oct 14, 2025
Episode 9 — Clause 5.3 — Roles, responsibilities, authorities
Oct 14, 2025
Episode 8 — Clause 5.1 + 5.2 — Leadership & policy evidence
Oct 14, 2025
Episode 7 — Clause 4.4 — ISMS processes and interactions
Oct 14, 2025
Episode 6 — Clause 4.3 — Determining ISMS scope
Oct 14, 2025
Episode 5 — Clause 4.1 + 4.2
Oct 14, 2025
Episode 4 — 27002 Attributes & the SoA
Oct 14, 2025
Episode 3 — What Changed
Oct 14, 2025
Episode 2 — ISMS & PDCA in Practice
Oct 14, 2025
Episode 1 — Orientation & Outcomes
Oct 14, 2025