Submind YouTube summaries
Thumbnail for WHY 2025 - ISMS-oxide and you (Information-Security-Management-System for hackers)

WHY 2025 - ISMS-oxide and you (Information-Security-Management-System for hackers)

Watch on YouTube

Video summary

The video explores the gap between theoretical Information Security Management Systems (ISMS) and their practical implementation, drawing on nearly two decades of experience in regulated environments. The speaker explains that standards like ISO 27001 are designed to ensure continuous improvement rather than guaranteeing immediate security or quality; they mandate the management of these aspects but leave the specific outcomes undefined. In an ideal scenario, a process-based system involves drafting policies by a central team, conducting internal audits for compliance, and managing risks where gaps between requirements and reality are formally accepted. However, the speaker argues that in reality, many organizations fail because staff do not fully understand how these processes apply to their specific systems, leading to a situation where procedures are followed merely for the sake of documentation—a phenomenon described as "performative art"—rather than to achieve genuine security improvements. A significant portion of the discussion focuses on the inherent challenges and potential for manipulation within risk management and certification processes. The speaker highlights that defining clear, non-overlapping risk classes is often difficult because businesses struggle to quantify impacts like operational downtime or reputational damage into precise financial figures, turning risk assessment into a guessing game. Furthermore, he points out conflicts of interest where auditors are paid by the organizations they inspect, which can lead to superficial checks that miss critical issues, such as outdated operating systems on web servers. While standards offer flexibility in scope and technical requirements, this can be exploited to create a "certificate of compliance" without actual security, forcing companies to maintain a good external appearance while ignoring internal vulnerabilities. To navigate these complexities, the speaker offers several practical recommendations for organizations and individuals involved in ISMS. He advises that a CISO or security lead must possess both hard skills in legal and business contexts and strong soft skills to communicate effectively across different departments. It is crucial to avoid relying on a single point of failure by ensuring there are backups for key personnel, especially in smaller enterprises. When seeking certification, the speaker recommends hiring auditors who genuinely challenge processes rather than those who simply rubber-stamp documents, suggesting that organizations switch auditors every two years to prevent complacency. Additionally, he encourages building trust and "karma points" within the organization so that security teams are viewed as helpful partners rather than obstacles, fostering an environment where issues are reported openly without fear of retribution. Ultimately, the video concludes that while ISMS frameworks provide a necessary structure, their success depends on human understanding and adaptability rather than rigid adherence to every technical detail. The speaker suggests simplifying risk matrices to avoid excessive complexity and using historical data to refine classifications over time. He also notes that while quantitative methods like Monte Carlo simulations exist, they are often too resource-intensive for most organizations unless all stakeholders are experts. By focusing on the spirit of the standards rather than just the letter, maintaining independence in audits, and fostering a culture of trust, organizations can achieve a more robust security posture that balances legal obligations with practical reality.
Read the full video transcript
[Music] Okay. So, um I've been doing IT security management for uh I would say close to 20 years. Before that, uh uh uh did pentest, security concepts, stuff like that. and um I've been in um mostly regulated uh environments um so uh quite a bit of exposure to uh legal requirements etc. Um and um the the second bullet point is sort of like the alphabetical what I know I've did quite a lot of it baseline protection from the German BSI and the last thing uh that I found in the alphabetical list is the fatron cigettes in Germany which is the trust trust services law um and obviously I'm from Germany so um agenda so we'll start a little bit about uh uh how our ISMS as opposed to uh uh what are they? Second uh how are they supposed to function versus reality? Um then hacking uh which is a bit short uh some anecdotes and uh then some recommendations uh depending on like uh what sort of your role is in um that. So management systems in general um there are um probably two that you know the one is the ISO 901 which is quality management and then the other one is uh 2701 um security management. Um the important thing about those um standards is they don't um uh in themselves um uh uh guarantee that you have quality or management. they make sure that you do management of quality, management of security and the idea is that by continuous improvement you'll get better. So that's an important fact to keep in mind. So um and also that applies to certifications. So if you have a certification for one of those, you're doing that stuff, but where you started off, where currently are and where you're ending up with um that's uh undefined, you know. So um ISMS so uh essentially you have a process because benchmarks are process based uh so you have uh you know documentation so policies procedures don't you know give your password away uh clean desk policy blah blah blah um and um the the central role for that is the um the I guess Caesar or whatever the the term is that's used um uh the that person or that team they draft up all the documents um essentially uh providing um all the uh people that are involved with guidelines on how they are supposed to uh do their work. Then the next uh important part is uh internal audits. So then those uh uh people go and check if uh uh everyone is complying with those things, right? And um uh the the last uh item risk incident management is about well you know we're supposed to do like uh 10 character passwords but our system only allows eight characters. What do we do now? Well you're uh um um not fulfilling uh with the requirements. So that's a risk per definition. So um essentially uh uh you write down the risk someone has to accept it and then everything is uh uh happy and with incidents more or less the same just not you know sort of planned but it just happens. So um CISO EO you know depends on the size of the organization um uh there's at least a dozen of uh uh role names that can be uh assigned. Uh the um two important uh um uh uh stakeholders is management because they are the ones who say okay we want to do this. We want to do security management because of legal obligations because of contractual obligation because we think it's a good idea. And then you have the people who are affected by by that so the stakeholders. So to give you um just a short uh uh visual idea. So um the the fireman is the the security management team. Then right next to it is the management and on the bottom you have sort of the uh the stakeholders. So one is supposed to be it the right hand side and the other one is you know whatever uh I couldn't find a better uh clip art that was uh you know unlim u uh public domain. So, um, management says, "Okay, hey, you guys, I pay your salary. You go do stuff, right? Here's your to-do list. Do that." Then management says, "Okay, hey, uh, security team, make sure we're safe, we're secure, right?" So, um, go do stuff. So um the uh security management team then uh okay hey you guys this is important you know do that passwords etc whatever um and um just like I said you know if if they can't be complied with then the Caesar goes okay hey we have a little issue here you know just uh something management to be aware of you have essentially two options just accept it so it's documented risk or throw you know resources is added and we'll solve it you know so theory and reality ISMS processes so already said this you know if processes are implemented and they continue to be uh uh um you know executed then essentially you you'll get better at the result and the result is your uh uh security neo posture whatever you want to call it so uh that's The core idea of all these management systems um in reality um the processes themselves are okay. Why don't we have effectively really good security everywhere is um because uh essentially all the people they don't get it you know oh we didn't know this applied to this system as well you know we thought that was sort of or we didn't even know about it and um the in my experience the real root cause is uh they don't get it now watch to the slide they don't get it so they don't get it they don't get ID. Um so it it makes everything complicated. So um just as an add-on um I just found this funny is uh create the infinite monkey theorem. So if you have an infinite number of monkeys operating an infinite number of ISMs will that lead to an effective ice mass? Well you know probably but that's probably not the strategy to go. So, um really, uh just you want a couple of good monkeys, so to say. Um and and that'll lead to great results. Um also, um processes are, you know, important. It's sort of like, uh this is the way we do things. But, um in real life things sometimes, uh you know, are done differently. So uh in order to uh then uh you know if some some customer so wants to audit you you need to show okay we've been doing this so uh sometimes the um process are uh you know just oh yeah let's do the process steps we we've already come to the conclusion we know what we do but let's document whatever the process says so that you know we we have that and that's uh a great term uh the performative art uh for that. So um next up risk management. So you have uh uh risk classes. So I have a low risk, a medium risk, a high risk and um you really want those to be uh non-over overlapping, right? You want okay up until this point it's a medium risk and from there on it's a high risk, right? So um that's the theory. In reality, even if you just uh consider um um just finance as a risk uh criteria. So if the damage is higher than€1 million euro, that's a high risk, right? But um what is uh what all accounts into that? If you have an outage, well maybe you can say, okay, we're losing €100,000 per hour, so after 10 hours it'll be a million. A high risk, right? But then there's other uh things to consider like what about the cleanup uh of the incident you know all that can be counted in and if you count everything in it'll becomes very diffuse in terms of what's the uh the number. So um everyone can sort of agree ah that's you know roughly 500,000 roughly 5 million but if you want to be more precise then it it really gets awkward and that's a problem obviously with clean edge uh risk classes. Well is this 900,000? Is it 1.1 million? We don't know. Well let's see. So um essentially it's more of a guessing game. then um the uh impact definition. So if you consider not only financial um criteria but also like operational impacts or reputational impacts um they should be um also uh defined in a way that um they don't uh overlap right so if you say okay let's just do financial criteria then um we can do yeah is it 900,000 1.1 million euro whatever um the reality is the business people um most often they can't put a number on things. They, you know, they're great with B business plans. So, oh yeah, we'll do build this and then we'll make this amount of um uh uh uh money. But if you ask them, well, what if this goes down? They're like, uh I don't know, you know. Um so, um again, guessing game. So next um and that's essentially it you know we can make informed decisions but um business can't put a number on it. So um I've seen this more often than uh less often is that it then says okay well we we've got the number of transaction okay we we can sort of put a number on it and um hey business why don't we take that number okay yeah let's do that you know but that's not how it's supposed to work okay so um certifications uh it's the next topic um when you want to get a certification um you're the organization, hey, I want to do this. So, uh but there's a step before that. So, you have a certification body, um the one that issues, uh essentially those certificates. And you have someone who is an auditor. Well, he's not an auditor yet. He's an expert. And actually, he's uh the expert. Does anyone get that reference? No. Okay. Uh look up the expert on YouTube. You'll like it. It's a 7-minute clip. Uh, one got it. Okay. So, uh, um, the expert, he has to go to the certification body and say, okay, hey, I want to be an auditor. Then he has to do some things, some trainings, whatever. And now he's an auditor, right? So, the organization is like, okay, we want to get one of those certificates. So, uh, hey certification body, can we have one of those? They're like, well, yeah. Um, it'll cost a bit, so give me some money. Right. So, um, oh yeah, here's a list of auditors that you can pick one from. Just, uh, go talk to them and they'll audit you. And if, uh, then you have a a positive result, then, uh, you'll get a certificate, right? So, next step is, well, we'll talk to the auditor. We'll give him some money. he'll go do stuff, you know, uh inspect everything, assess everything that's uh reliant and then if in the end, you know, you'll get a certificate. Hey, so um obviously there's a a conflict of interest, right? Um the auditor is paid by the organization, but he has to adhere to all the standards, etc. set forth by the certification body, and that's uh a non-resolvable conflict of interest, right? So if um uh you um get one of those certifications, it's important. They attest that you have those processes. They don't say that uh they don't really say anything about the quality of what the result is, right? Um and uh then the the question is how are how comparable are certifications? Can I have a certification ISO 2701? Great. I have another vendor here. Oh, we also have one. How can I compare those? And there's really two uh major factors in that. The one is scope. I can freely define my scope. I can be like a software as a service provider and define the scope of just my office. So like you know HR whatever and I have a certificate. Yay. You know so scope is the first one. But even if you um uh say okay I have two certificates that are sort of equivalent in terms of scope are they comparable? No. Because the depth of the uh audit of the auditor is really important. If you have an auditor who is great at pro uh assessing like are your processes functioning etc then he's a great auditor in terms of ISO 2701. if he doesn't know much about it, he might just say, "Yeah, well, you know, that Windows 7 web server that you have, you have a risk uh acceptance for that. You're fine." you know. So, and then there's the uh the German IT gut which is essentially um uh just an ISMS like the process um based thing but um the uh um the the add-on that they give with it is they give you technical requirements or process requirements. So, um something like well if you have a Windows 2019 server you need to set this setting to B. you know that they they do that. Um, and this catalog is uh is huge, but it's not so well maintained. Um, but uh it's still uh you know it's better than nothing. So um they they're really um putting amounts of effort in it but you know the the subject is huge. I mean you we're talking about potentially every aspect of it that they need to cover, right? Um but the point here is um they have um sort of hard requirements like what you need to do to get the certificate uh in the end and one is yet you have need to have the documentation based on their uh process and templates etc and that needs to be complete. So if you're missing one attribute in one document like uh for example you have a list of your IT infrastructure and uh it says okay we have a server and it's uh Windows uh 2019 and um but we missed put to put in like who's the uh admin team in charge of it right well you won't get a certificate that's a hard criteria so that um needs to be fixed whereas as the example the Windows 7 web server just the same thing. Hey, let's oh, you know, so um let's go on with the uh the next topic uh which is uh hacking in ISMS. Um did I click? My slides are lagging a bit so I don't know if I clicked or clicked didn't click. There you go. Okay. So, uh I guess you already got the impression ISO 27,01 has a lot of potential for fool's gold. So, something that shines but isn't really all that great. But, um you know, the scope uh uh hacking we talked about. Um then you can just define your own risk criteria. You can say, okay, we're a 10 uh people uh 10 person based company. You know, we make like uh 5 million per year or something like that. And our risk uh class for medium starts at 10 million. So all we have is low risks, you know. So um you can um tweak those to to you know have a better picture in the end. Um and then you know if you really want to if if you're like you know I want to make my own life easier as a CEO. Yeah. Well let me do internal audits that are just you know essentially worthless. Let me do um let me test those systems that are wellmaintained. Let me just ignore the uh you know the Windows 7 web server over there or whatever. And the last part is for certification. When you get the auditor, you know, if you get a one-trick auditor uh uh that you know uh knows everything about physical security who complains that you know like your fire door doesn't match to the the the door frame uh uh fire uh classes, then uh you know he's like we you need to work on that. But uh a real life experience. Oh, that Windows XP thingy over there. Ah, it's fine, you know. So, um that's a lot of ways where you can manipulate the whole system sort of. And then, um I have one specific fake for the uh the Oh, all right. Um if you do that, you need to uh you know, keep appearance. So, make sure when someone like someone who's interested, a potential customer, they scan you, you know, make sure that looks great. Um because otherwise they'll be like well you have the certificate but we found like this whole mess on the internet about you. Um they they might ask questions you know make sure that uh external security posture is is okay and uh then you'll be uh sort of okay on your way. So for uh the uh BSI IT baseline protection there's also one hack which is um they provide with all these um um uh uh catalogs like one is for Windows, one is for Linux etc. If you don't like what's in there, you can just define your own. Well, we don't like the uh requirement for enabling SE Linux in the uh the Linux catalog. Well, let's make our own. Let's make our um I don't know Debian Linux catalog and we'll just skip on the SA Linux. So you're you know you're free to sort of uh build your own set of requirements there which is a bit of work but you know if if that's um what you want to do. So uh let's get on to the uh the funny stories real life experiences. Um and I mentioned this I I worked in a regulated environment. So um this was one of the most highly recom uh regulated environments. Anything you can think of um that um that can be put forth on you as a service provider was contractually uh uh regulated. So um everything you know like what they did is essentially you know then you um build up a uh like a project uh team that uh you know does all these things and um especially for ISMS you have people who review documents you have other people who do pentest etc and stuff um but still stuff happens so um I just really want I was working on a different project and I just wanted to copy and paste something from from a document that I knew they had, you know, content that I sort of also needed. So I uh opened their document and um found the the part in the document that I was looking for. And so like, oh yeah, and that has also the reference to the corporate document. So but wait, that reference that reference document that was invalidated at least four years ago at the time. Okay. Um, how does that happen? Should that happen? No, because uh you know uh the document needs to be reviewed regularly. So, but yeah, the document had been uh reviewed twice since then. So, should have been caught, right? Well, you know, that can happen. They didn't, you know, see it. It's uh you know um but um there's another aspect and um that's they didn't look at it because that cited passages a passage that they they inserted in a document it had windings as the font. Windings if you don't know it's the symbol font so there was nothing to see there you know got the word document changed the font to uh you know whatever times times romo or whatever and yes it it had the right text but it just you know and that's you know in an environment where you say okay this is as good as it gets so stuff happens. So next up um and this is uh one of my uh my f personal favorites is um a different project. We um from a customer we got a secure or compliance questionnaire. You you probably know all those right? Anybody not having experience with compliance questionnaires? Okay. So um you know it was just all the same except for one question and we had just enjoyed that question so much. The question was, do you have any wastewater or sewage pipelines running above your IT equipment? And you know, every question that's asked has a story to it. And I just pity the person that had to just, you know, pull do all the cleanup work there. So yes. So um recommendations snakes up. So if um you're an organization get it CISO you know um and it really well it can hurt but um the important part is you need to get someone who understands both the business aspects the legal aspects and it those are the uh uh sort of uh hard skill sort of requirements uh to be uh uh you know in a um in an effective uh uh domain and um then of course soft skills are important as well. You don't want that uh you know uh person who knows all this stuff but just doesn't interact with anybody. So you need to get someone who's you know so uh social. Um and then you have one you know maybe you're not a large organization make sure you have a backup. You don't want your bus factor to be one. You don't want that one person who runs the show to uh you know just quit the job or uh you know have an accident or whatever. Make sure you have a a backup. So, small and medium enterprises and um just adapt as you move along you know um I would say those uh uh two things are really the important ones and um if you want to get a certification get a good auditor you know uh good in terms of someone who really challenges you uh both in terms of processes both in terms of IT and uh all the other stuff um and uh usually the certification cycles for 3 years. So you have an audit every year but every 3 years you get a new certificate. After two certification cycles, I would recommend that you get another auditor just so you don't get the uh you know the burnin on on you know whatever you want a different opinion you know so um if you're working in an ISMS you know be social establish uh trust you don't want uh you know uh uh FUD to be your your uh your your working principle you don't trust to be the uh working principle cuz then people like from it will come to you and say okay hey you know we have this issue okay yeah essentially I mean that's a risk you know we we we'll handle it you know but you want those guys and and girls whoever to come to you and tell you okay you know you won't uh get mad at you etc so um you know build trust also it helps to build uh up karma points So um if you uh and you know that's presumably uh applies to all of you here, you know it, you can help them at time. You can be like what are you working on? Oh wait, I know that. Did you try this? And they'll be so grateful. So build up commer points. Um as for risk classes, settle for less. You know, if you have like six risk classes and a risk matrix in terms of um um uh impact and um probability, you get so many uh edges where like is that here, is that there? Is it there? You know, it's the guess work. So 3x3 is also just good enough. You know, most often it'll be 4x4, but um um do that. Then if you want to uh you can you have an option of doing um risk analysis in in two means. One is to say okay let's say um we have a million as the financial category for impact and well yeah we're above a million right well you can do quantitative risk analysis which is essentially a Monte Carlo simulation where uh you'll get a result that in the end should be more appropriate but this whole thing is mathematically so complex and requires so many input data. You really don't want to do that. The um the uh only uh time you want to do that is when everyone involved and I mean I'm talking like the people in security management. I'm talking about the people in management and uh the stakeholders all the other people right you you just want to do that if everyone is an expert. And uh now for another uh reference. Ah, the audio is not playing. Let me do that again. Can you turn on the uh the audio from the laptop? Okay. So, um the uh the expert. Okay. He's saying, you know, hey, I'm Scott Williams and I'm the expert. If you watch the uh the sketch, the seven minute uh the expert sketch, the solution is uh the you know, you're like, what? Now that can be done, right? Well, he found a solution. So, got to watch the uh the expert solution uh as well as a one or two minute clip. So, um when you're in ISMS uh jobs, you need to address your audiences appropriately. You need a different uh language when you're talking to HR. You need a different language when talking to IT, etc., etc. um know that you know um also look at the past. If you've done this for a couple years, you have so much data. You have like probably dozens or hundreds of risk in your risk register. Some that have been uh closed off uh have been done away with. Use that data to evaluate whether or not um the classification was appropriate. you know, like your end result might be, well, we have a 5x5 risk matrix. Um, it clusters around the uh the middle section. We can do away with at least one column, one uh one line. So, um just use whatever data you collected over the years to uh to improve. And also important when you're working in uh such a field you get contact with lots and lots of things that um are supposed to happen like strategy from management uh projects that haven't been announced yet. Uh you uh get uh contact with individual projects that they might not know about each other. So use that insight to help those people get their job done better. tell them, okay, you should talk to that project over there with that person because he solved uh the problem that you're working on already. So, um and of course there's times when you can't because you know it's something that's still under uh um uh that's under you know NDA or something but you know if appropriate do that. So, and for everybody else, when you're interacting with uh people from an ISMS, um don't expect too much of an IT knowledge. You know, you might be lucky uh you might have some people there, cherish those, especially in larger organizations when like the ISMs team might be like 30 50 people. If you know like the two or three maybe that have IT skills, you need to connect with them because they are your entry door into the whole ISMS organization. If you need to get something done, they are your entry door. Um give feedback, you know, they they're all just doing their job. Um and also and that's uh sort of what I uh um have been uh trying to do is get people that know it to get into ISMS, get into security management. Um but I would only recommend that to people who can put up with documentation work, who can put up with dealing with people that don't know too much about it or whatever. So be uh you have to have a certain level of patience etc. And um but if if that fits you, go into that because you have uh lots of insights into your organization. You have uh you build up a lot of knowledge about uh surrounding like uh legal uh stuff. You know, you just find yourself, let me read through that law, let me go talk to our corporate lawyer, whatever. You learn stuff that you didn't expect. And also career-wise, that's you know, not a smart move. Security is in demand. So um that was it. I am just on time. So now we're on to uh questions. [Applause] >> Yes, question. Thanks for your talk. Um would you agree in regards to ISO standards that there should be more safeguards into them to make sure that people don't scoot them like make them easy to get etc. Um well the the whole story is that the uh especially the ISO 2701 they have an annex which contains uh technical uh or pro procedural also requirements. So uh things like you need to do patch management you know so more specific things uh you need to do access control you need to have a concept etc. Um so the picture I painted isn't the whole picture but it's still a um just an uh an overarching uh uh uh standard because it has to be suitable for small medium enterprises to you know uh the largest uh organizations that we have on earth. So, um I think it it's it's already at where it should be. What I really think where they should improve is um the the auditors um because they essentially you know what they their idea is well you have an auditor who can assess whatever is written in the those standards. He's a auditor, right? That's only half the story, you know. Um, a good auditor will be like, "Okay, well, you just told me this yesterday in our audit session. I heard this from a different team, whatever. How does that map, you know?" Um, and th those are things when uh, you know, especially if that comes out to be an issue where you're like, "Oh, wow." You know, yes. Um, where you can really improve. So I would say it's more the auditors that are the uh where you where improvement needs to happen and that's what I sort of like about the uh the German baseline protection center is because it has a lot more of those the detailed technical requirements but as well as there you have auditors who will be like do you have that can you show me yes I'll show you a document can you show me on the system we'll put up something on the screen they'll be like okay yeah and you're like we I haven't even reached the screen where that setting is you know so yeah >> yeah thank you very much for the talk um could you briefly sketch the steps which are necessary to become an auditor for instance uh with regard to Wi-Fi security >> okay um the the the so there's Like auditor is a broad class, right? Is someone who you essentially pay to assess something. The question is assessing against what baseline against what standard? Um and um when you're talking about like Wi-Fi, it I I was I would be more thinking about something like a pentest, you know, so hey, just you know, pentest our uh Wi-Fi. Um so um essentially the um the the audits that in terms of audit which is almost always like um first um check how it's supposed to be done. So documents what are the process what are the the security levels security settings that are supposed to set and then check the implementation is that also the case um and um essentially like the the standards there's um uh now improving number of legal uh uh uh like laws where uh things that have to be audited against like the um the critical infrastructure. So uh NIS 2 well if there is a NIS 2 there's a NIS one NIS one is about critical infrastructure in uh Europe. So uh I think the the the baseline was uh if you're providing services out of some categories like telecommunications water food etc. And if you're serving more than 500,000 people your critical infrastructure and then you need to uh have uh like I think it's annual audits. So those are auditors who test against the the legal uh um uh requirements, right? Um so the the question is really about what setting would be a setting where you test against specifically for Wi-Fi and the only thing I can think of right now is uh if uh um uh if it's a product and that product um is the manage says okay we need to get a common criteria certification because common criteria is a product certification so then you could be an auditor for Wi-Fi or whatever you know and um do that. Um essentially uh it comes down to um independent of what you are you need to um uh essentially um demonstrate knowledge uh either because you have been already working with them and they say okay yeah we know you you're good uh but you still have to do the uh some sort of you know test or whatever assessment um in order to comply with their processes. Um but most often it'll be something like well do this training at the end of the training you'll do this assessment and uh then um you'll be an auditor and then as an auditor you need to sign like okay I will buy to whatever principles the organization set forth etc. Uh I will do like annual uh training to you know keep my skills up to date etc. So there's a a lot of side work that an auditor uh needs to do sort of just like any you know personal certification. So um um and then um most often when you uh get a a contract uh um from from some company to do an audit, you also then again have to sign a letter of independence. Okay, I'm uh you know they pay me but I'm independent and um uh there's in real life the the order well I cannot you ask well okay we have this issue order says okay that's something you need to work on and you're like well what do you suggest and the auditor will be like I can't suggest you because that will be consulting and I'm not allowed to consult you with uh how you do right but you can um with most auditors you can sort of play the question and answer game if we do it that Okay. Would that be good enough? May. No. Well, if we do it that way, yes. So, um they they know about their double roll is essentially what I'm saying. Okay. Hello. Yeah. Actually have some tips from my own experience as a Dutch uh company with around 10 people. Um about the auditors I think in the Netherlands at least uh there also quite some decent ones but it depends a bit on their organization because they have their own um guidelines sort of some are really like uh religious on the letter >> and others are more of in the spirit or they see if you have this addressed properly. >> Yeah. >> Uh even then they judge on that. And um what I also recommend if you looking for an internal auditor actually get an external auditor independent for example and use that one because they are actively does external audits >> because they know what the latest stuff is with interpretation of certain rules >> right >> and also ask them for example um to keep an eye out on the stuff you do which is actually not required by the standard because often you see people if they have the requirements they make stuff up. Uh you should fried what you do, >> right? >> But then they fried stuff or start doing stuff because they think it's what's needed. >> Yeah. >> Um and then you get that the internal auditor which asks like, well, where does it say that you have to do that, >> right? >> And then you can cut the crap from your ISMS as well. >> And um yeah, and involve a lot of people. I think that we for us uh we pull in the team members who are uh in their if their stuff is being audited we always pull in the person who actually does the work >> and all the processes we have are actually the ISMS processes is only very separate a small part is only EMS only the rest is all the the EMS basically all the company documentation >> and um yeah keep it simple >> I think it's really Uh the ESO is actually really easy if you did it a few times and have it on the writt and then >> um if you do some other certifications and it's pretty easy. >> Yeah. Yeah. No, especially the ISO 2701 if you have a a corporate setup uh where can you effectively do work and just like you said if you have done this a few times a oneerson show can can run the show. um you want a backup, right? Um so you want someone to to go along, but you don't need five people in in that domain. Um yes, that's a stressy job then, but it's possible. And uh why am I saying that? Because that's what I'm currently doing. Then I want to thank you again for having great making this great talk and thank you for the great questions. Give it up once again for Jurgen. >> Thank you. And then enjoy the rest of the camp.