WHY 2025 - ISMS-oxide and you (Information-Security-Management-System for hackers)
Watch on YouTubeVideo summary
The video explores the gap between theoretical Information Security Management Systems (ISMS) and their practical implementation, drawing on nearly two decades of experience in regulated environments. The speaker explains that standards like ISO 27001 are designed to ensure continuous improvement rather than guaranteeing immediate security or quality; they mandate the management of these aspects but leave the specific outcomes undefined. In an ideal scenario, a process-based system involves drafting policies by a central team, conducting internal audits for compliance, and managing risks where gaps between requirements and reality are formally accepted. However, the speaker argues that in reality, many organizations fail because staff do not fully understand how these processes apply to their specific systems, leading to a situation where procedures are followed merely for the sake of documentation—a phenomenon described as "performative art"—rather than to achieve genuine security improvements.
A significant portion of the discussion focuses on the inherent challenges and potential for manipulation within risk management and certification processes. The speaker highlights that defining clear, non-overlapping risk classes is often difficult because businesses struggle to quantify impacts like operational downtime or reputational damage into precise financial figures, turning risk assessment into a guessing game. Furthermore, he points out conflicts of interest where auditors are paid by the organizations they inspect, which can lead to superficial checks that miss critical issues, such as outdated operating systems on web servers. While standards offer flexibility in scope and technical requirements, this can be exploited to create a "certificate of compliance" without actual security, forcing companies to maintain a good external appearance while ignoring internal vulnerabilities.
To navigate these complexities, the speaker offers several practical recommendations for organizations and individuals involved in ISMS. He advises that a CISO or security lead must possess both hard skills in legal and business contexts and strong soft skills to communicate effectively across different departments. It is crucial to avoid relying on a single point of failure by ensuring there are backups for key personnel, especially in smaller enterprises. When seeking certification, the speaker recommends hiring auditors who genuinely challenge processes rather than those who simply rubber-stamp documents, suggesting that organizations switch auditors every two years to prevent complacency. Additionally, he encourages building trust and "karma points" within the organization so that security teams are viewed as helpful partners rather than obstacles, fostering an environment where issues are reported openly without fear of retribution.
Ultimately, the video concludes that while ISMS frameworks provide a necessary structure, their success depends on human understanding and adaptability rather than rigid adherence to every technical detail. The speaker suggests simplifying risk matrices to avoid excessive complexity and using historical data to refine classifications over time. He also notes that while quantitative methods like Monte Carlo simulations exist, they are often too resource-intensive for most organizations unless all stakeholders are experts. By focusing on the spirit of the standards rather than just the letter, maintaining independence in audits, and fostering a culture of trust, organizations can achieve a more robust security posture that balances legal obligations with practical reality.
Read the full video transcript
[Music]
Okay. So, um I've been doing IT security
management for uh I would say close to
20 years. Before that, uh uh uh did
pentest, security concepts, stuff like
that. and um I've been in um mostly
regulated uh environments um so uh quite
a bit of exposure to uh legal
requirements etc. Um and um the the
second bullet point is sort of like the
alphabetical
what I know I've did quite a lot of it
baseline protection from the German BSI
and the last thing uh that I found in
the alphabetical list is the fatron
cigettes in Germany which is the trust
trust services law um and obviously I'm
from Germany so
um agenda so we'll start a little bit
about uh uh how our ISMS as opposed to
uh uh what are they? Second uh how are
they supposed to function versus
reality? Um then hacking uh which is a
bit short uh some anecdotes and uh then
some recommendations uh depending on
like uh what sort of your role is in um
that. So management systems in general
um there are um probably two that you
know the one is the ISO 901 which is
quality management and then the other
one is uh 2701
um security management. Um the important
thing about those um standards is they
don't um uh in themselves um uh uh
guarantee that you have quality or
management. they make sure that you do
management of quality, management of
security and the idea is that by
continuous improvement you'll get
better. So that's an important fact to
keep in mind. So um and also that
applies to certifications. So if you
have a certification for one of those,
you're doing that stuff, but where you
started off, where currently are and
where you're ending up with um that's uh
undefined, you know. So
um ISMS
so uh essentially you have a process
because benchmarks are process based uh
so you have uh you know documentation so
policies procedures don't you know give
your password away uh clean desk policy
blah blah blah um and um the the central
role for that is the um the I guess
Caesar or whatever the the term is
that's used um uh the that person or
that team they draft up all the
documents um essentially uh providing um
all the uh people that are involved with
guidelines on how they are supposed to
uh do their work. Then the next uh
important part is uh internal audits. So
then those uh uh people go and check if
uh uh everyone is complying with those
things, right? And um uh the the last uh
item risk incident management is about
well you know we're supposed to do like
uh 10 character passwords but our system
only allows eight characters. What do we
do now? Well you're uh um um not
fulfilling uh with the requirements. So
that's a risk per definition. So um
essentially uh uh you write down the
risk someone has to accept it and then
everything is uh uh happy and with
incidents more or less the same just not
you know sort of planned but it just
happens.
So
um CISO EO you know depends on the size
of the organization um uh there's at
least a dozen of uh uh role names that
can be uh assigned. Uh the um two
important uh um uh uh stakeholders is
management because they are the ones who
say okay we want to do this. We want to
do security management because of legal
obligations because of contractual
obligation because we think it's a good
idea. And then you have the people who
are affected by by that so the
stakeholders. So to give you um just a
short uh uh visual idea. So um the the
fireman is the the security management
team. Then right next to it is the
management and on the bottom you have
sort of the uh the stakeholders. So one
is supposed to be it the right hand side
and the other one is you know whatever
uh I couldn't find a better uh clip art
that was uh you know unlim u uh public
domain. So, um, management says, "Okay,
hey, you guys, I pay your salary. You go
do stuff, right? Here's your to-do list.
Do that." Then management says, "Okay,
hey, uh, security team, make sure we're
safe, we're secure, right?" So, um, go
do stuff. So um the uh security
management team then uh okay hey you
guys
this is important you know do that
passwords etc whatever um and um just
like I said you know if if they can't be
complied with then the Caesar goes okay
hey we have a little issue here you know
just uh something management to be aware
of you have essentially two options just
accept it so it's documented risk or
throw you know resources is added and
we'll solve it you know
so theory and reality ISMS processes
so already said this you know if
processes are implemented and they
continue to be uh uh um you know
executed then essentially you you'll get
better at the result and the result is
your uh uh security neo posture whatever
you want to call it so uh that's The
core idea of all these management
systems
um in reality
um the processes themselves are okay.
Why don't we have effectively really
good security everywhere is um because
uh essentially all the people they don't
get it you know oh we didn't know this
applied to this system as well you know
we thought that was sort of or we didn't
even know about it and um the in my
experience the real root cause is uh
they don't get it now watch to the slide
they don't get it so
they don't get it they don't get ID. Um
so it it makes everything complicated.
So um just as an add-on um I just found
this funny is uh create the infinite
monkey theorem. So if you have an
infinite number of monkeys operating an
infinite number of ISMs will that lead
to an effective ice mass? Well you know
probably but that's probably not the
strategy to go. So, um really, uh just
you want a couple of good monkeys, so to
say. Um and and that'll lead to great
results. Um also, um processes are, you
know, important. It's sort of like, uh
this is the way we do things. But, um in
real life things sometimes, uh you know,
are done differently. So uh in order to
uh then uh you know if some some
customer so wants to audit you you need
to show okay we've been doing this so uh
sometimes the um process are uh you know
just oh yeah let's do the process steps
we we've already come to the conclusion
we know what we do but let's document
whatever the process says so that you
know we we have that and that's uh a
great term uh the performative art uh
for that. So
um next up risk management. So you have
uh uh risk classes. So I have a low
risk, a medium risk, a high risk and um
you really want those to be uh non-over
overlapping, right? You want okay up
until this point it's a medium risk and
from there on it's a high risk, right?
So um that's the theory. In reality,
even if you just uh consider um
um just finance as a risk uh criteria.
So if the damage is higher than€1
million euro, that's a high risk, right?
But um what is uh what all accounts into
that? If you have an outage, well maybe
you can say, okay, we're losing €100,000
per hour, so after 10 hours it'll be a
million. A high risk, right? But then
there's other uh things to consider like
what about the cleanup uh of the
incident you know all that can be
counted in and if you count everything
in it'll becomes very diffuse in terms
of what's the uh the number. So um
everyone can sort of agree ah that's you
know roughly
500,000 roughly 5 million but if you
want to be more precise then it it
really gets awkward and that's a problem
obviously with clean edge uh risk
classes. Well is this 900,000? Is it 1.1
million? We don't know. Well let's see.
So um essentially it's more of a
guessing game.
then um the uh impact definition. So if
you consider not only financial um
criteria but also like operational
impacts or reputational impacts um they
should be um also uh defined in a way
that um they don't uh overlap right so
if you say okay let's just do financial
criteria then um we can do yeah is it
900,000 1.1 million euro whatever um the
reality is the business people um most
often they can't put a number on things.
They, you know, they're great with B
business plans. So, oh yeah, we'll do
build this and then we'll make this
amount of um uh uh uh money. But if you
ask them, well, what if this goes down?
They're like, uh
I don't know, you know. Um so, um again,
guessing game.
So next
um and that's essentially it you know we
can make informed decisions
but um
business can't put a number on it. So um
I've seen this more often than uh less
often is that it then says okay well we
we've got the number of transaction okay
we we can sort of put a number on it and
um hey business why don't we take that
number okay yeah let's do that you know
but that's not how it's supposed to work
okay so um certifications uh it's the
next topic um
when you want to get a certification um
you're the organization, hey, I want to
do this. So, uh but there's a step
before that. So, you have a
certification body, um the one that
issues, uh essentially those
certificates. And you have someone who
is an auditor. Well, he's not an auditor
yet. He's an expert. And actually, he's
uh the expert. Does anyone get that
reference?
No. Okay. Uh look up the expert on
YouTube. You'll like it. It's a 7-minute
clip. Uh, one got it. Okay. So, uh, um,
the expert, he has to go to the
certification body and say, okay, hey, I
want to be an auditor. Then he has to do
some things, some trainings, whatever.
And now he's an auditor, right? So, the
organization is like, okay, we want to
get one of those certificates. So, uh,
hey certification body, can we have one
of those? They're like, well, yeah. Um,
it'll cost a bit, so give me some money.
Right.
So, um, oh yeah, here's a list of
auditors that you can pick one from.
Just, uh, go talk to them and they'll
audit you. And if, uh, then you have a a
positive result, then, uh, you'll get a
certificate, right? So, next step is,
well, we'll talk to the auditor. We'll
give him some money. he'll go do stuff,
you know, uh inspect everything, assess
everything that's uh reliant and then if
in the end, you know, you'll get a
certificate. Hey, so um obviously
there's a a conflict of interest, right?
Um the auditor is paid by the
organization, but he has to adhere to
all the standards, etc. set forth by the
certification body, and that's uh a
non-resolvable conflict of interest,
right?
So
if um uh you um get one of those
certifications, it's important. They
attest that you have those processes.
They don't say that uh they don't really
say anything about the quality of what
the result is, right? Um and uh then the
the question is how are how comparable
are certifications? Can I have a
certification ISO 2701?
Great. I have another vendor here. Oh,
we also have one. How can I compare
those? And there's really two uh major
factors in that. The one is scope. I can
freely define my scope. I can be like a
software as a service provider and
define the scope of just my office. So
like you know HR whatever and I have a
certificate. Yay. You know so scope is
the first one. But even if you um uh say
okay I have two certificates that are
sort of equivalent in terms of scope are
they comparable? No. Because the depth
of the uh audit of the auditor is really
important. If you have an auditor who is
great at pro uh assessing like are your
processes functioning etc then he's a
great auditor in terms of ISO 2701. if
he doesn't know much about it, he might
just say, "Yeah, well, you know, that
Windows 7 web server that you have, you
have a risk uh acceptance for that.
You're fine." you know. So, and then
there's the uh the German IT gut which
is essentially um uh just an ISMS like
the process um based thing but um the uh
um the the add-on that they give with it
is they give you technical requirements
or process requirements. So, um
something like well if you have a
Windows 2019
server you need to set this setting to
B. you know that they they do that. Um,
and this catalog is uh is huge, but it's
not so well maintained. Um, but uh it's
still uh you know it's better than
nothing. So um they they're really um
putting amounts of effort in it but you
know the the subject is huge. I mean you
we're talking about potentially every
aspect of it that they need to cover,
right? Um but the point here is um they
have um sort of hard requirements like
what you need to do to get the
certificate uh in the end and one is yet
you have need to have the documentation
based on their uh process and templates
etc and that needs to be complete. So if
you're missing one attribute in one
document like uh for example you have a
list of your IT infrastructure and uh it
says okay we have a server and it's uh
Windows uh 2019
and um but we missed put to put in like
who's the uh admin team in charge of it
right well you won't get a certificate
that's a hard criteria so that um needs
to be fixed whereas as the example the
Windows 7 web server just the same
thing. Hey, let's oh, you know, so um
let's go on with the uh the next topic
uh which is uh hacking in ISMS. Um
did I click? My slides are lagging a bit
so I don't know if I clicked or clicked
didn't click. There you go. Okay. So, uh
I guess you already got the impression
ISO 27,01 has a lot of potential for
fool's gold. So, something that shines
but isn't really all that great. But, um
you know, the scope uh uh hacking we
talked about. Um then you can just
define your own risk criteria. You can
say, okay, we're a 10 uh people uh 10
person based company. You know, we make
like uh 5 million per year or something
like that. And our risk uh class for
medium starts at 10 million. So all we
have is low risks, you know. So um you
can um tweak those to to you know have a
better picture in the end. Um and then
you know if you really want to if if
you're like you know I want to make my
own life easier as a CEO. Yeah. Well let
me do internal audits that are just you
know essentially worthless. Let me do um
let me test those systems that are
wellmaintained. Let me just ignore the
uh you know the Windows 7 web server
over there or whatever. And the last
part is for certification. When you get
the auditor,
you know, if you get a one-trick auditor
uh uh that you know uh knows everything
about physical security who complains
that you know like your fire door
doesn't match to the the the door frame
uh uh fire uh classes, then uh you know
he's like we you need to work on that.
But uh a real life experience. Oh, that
Windows XP thingy over there. Ah, it's
fine, you know. So, um that's a lot of
ways where you can manipulate the whole
system sort of. And then, um I have one
specific fake for the uh the Oh, all
right. Um if you do that, you need to uh
you know, keep appearance. So, make sure
when someone like someone who's
interested, a potential customer, they
scan you, you know, make sure that looks
great. Um because otherwise they'll be
like well you have the certificate but
we found like this whole mess on the
internet about you. Um they they might
ask questions you know make sure that uh
external security posture is is okay and
uh then you'll be uh sort of okay on
your way. So for uh the uh BSI IT
baseline protection there's also one
hack which is um they provide with all
these um um uh uh catalogs like one is
for Windows, one is for Linux etc. If
you don't like what's in there, you can
just define your own. Well, we don't
like the uh requirement for enabling SE
Linux in the uh the Linux catalog. Well,
let's make our own. Let's make our um I
don't know Debian Linux catalog and
we'll just skip on the SA Linux. So
you're you know you're free to sort of
uh build your own set of requirements
there which is a bit of work but you
know if if that's um what you want to
do. So uh let's get on to the uh the
funny stories real life experiences. Um
and I mentioned this I I worked in a
regulated environment. So um this was
one of the most highly recom uh
regulated environments.
Anything you can think of um that um
that can be put forth on you as a
service provider
was contractually uh uh regulated. So um
everything you know like
what they did is essentially you know
then you um build up a uh like a project
uh team that uh you know does all these
things and um especially for ISMS you
have people who review documents you
have other people who do pentest etc and
stuff um but still stuff happens so um I
just really want I was working on a
different project and I just wanted to
copy and paste something from from a
document that I knew they had, you know,
content that I sort of also needed. So I
uh opened their document and um found
the the part in the document that I was
looking for. And so like, oh yeah, and
that has also the reference to the
corporate document. So but wait,
that reference that reference document
that was invalidated at least four years
ago at the time.
Okay.
Um, how does that happen? Should that
happen? No, because uh you know uh the
document needs to be reviewed regularly.
So, but yeah, the document had been uh
reviewed twice since then. So, should
have been caught, right?
Well, you know, that can happen. They
didn't, you know, see it. It's uh you
know um
but um there's another aspect and um
that's they didn't look at it because
that cited passages a passage that they
they inserted in a document it had
windings as the font.
Windings if you don't know it's the
symbol font so there was nothing to see
there you know got the word document
changed the font to uh you know whatever
times times romo or whatever and yes it
it had the right text but it just you
know and that's you know in an
environment where you say okay this is
as good as it gets so stuff happens.
So next up um and this is uh one of my
uh my f personal favorites is um a
different project. We um from a customer
we got a secure or compliance
questionnaire. You you probably know all
those right? Anybody not having
experience with compliance
questionnaires? Okay. So um you know it
was just all the same except for one
question and we had just enjoyed that
question so much. The question was,
do you have any wastewater or sewage
pipelines running above your IT
equipment? And you know, every question
that's asked has a story to it. And I
just pity the person that had to just,
you know, pull do all the cleanup work
there. So
yes. So um
recommendations
snakes up. So if um you're an
organization
get it CISO you know um and it really
well it can hurt but um the important
part is you need to get someone who
understands both the business aspects
the legal aspects and it
those are the uh uh sort of uh hard
skill sort of requirements uh to be uh
uh you know in a um in an effective uh
uh domain and um then of course soft
skills are important as well. You don't
want that uh you know uh person who
knows all this stuff but just doesn't
interact with anybody. So you need to
get someone who's you know so uh social.
Um and then you have one you know maybe
you're not a large organization make
sure you have a backup. You don't want
your bus factor to be one. You don't
want that one person who runs the show
to uh you know just quit the job or uh
you know have an accident or whatever.
Make sure you have a a backup. So, small
and medium enterprises and um just adapt
as you move along you know um I would
say those uh uh two things are really
the important ones and um if you want to
get a certification get a good auditor
you know uh good in terms of someone who
really challenges you uh both in terms
of processes both in terms of IT and uh
all the other stuff um and uh usually
the certification cycles for 3 years. So
you have an audit every year but every 3
years you get a new certificate. After
two certification cycles, I would
recommend that you get another auditor
just so you don't get the uh you know
the burnin on on you know whatever you
want a different opinion you know
so um
if you're working in an ISMS
you know be social establish uh trust
you don't want uh you know uh uh FUD to
be your your uh your your working
principle you don't trust to be the uh
working principle cuz then people like
from it will come to you and say okay
hey you know we have this issue okay
yeah essentially I mean that's a risk
you know we we we'll handle it you know
but you want those guys and and girls
whoever to come to you and tell you okay
you know you won't uh get mad at you etc
so um you know build trust also it helps
to build uh up karma points So um if you
uh and you know that's presumably uh
applies to all of you here, you know it,
you can help them at time. You can be
like what are you working on? Oh wait, I
know that.
Did you try this? And they'll be so
grateful. So build up commer points. Um
as for risk classes, settle for less.
You know, if you have like six risk
classes and a risk matrix in terms of um
um uh impact and um probability,
you get so many uh edges where like is
that here, is that there? Is it there?
You know, it's the guess work. So 3x3 is
also just good enough. You know, most
often it'll be 4x4, but um
um do that. Then if you want to uh you
can you have an option of doing um risk
analysis in in two means. One is to say
okay let's say um we have a million as
the financial category for impact and
well yeah we're above a million right
well you can do quantitative risk
analysis which is essentially a Monte
Carlo simulation where uh you'll get a
result that
in the end should be more appropriate
but this whole thing is mathematically
so complex and requires so many input
data. You really don't want to do that.
The um the uh only uh time you want to
do that is when everyone involved and I
mean I'm talking like the people in
security management. I'm talking about
the people in management and uh the
stakeholders all the other people right
you you just want to do that if everyone
is an expert. And uh now for another uh
reference.
Ah, the audio is not playing.
Let me do that again.
Can you turn on the uh the audio from
the laptop? Okay.
So, um the uh the expert.
Okay. He's saying, you know, hey, I'm
Scott Williams and I'm the expert. If
you watch the uh the sketch, the seven
minute uh the expert sketch,
the solution is uh the you know, you're
like, what? Now that can be done, right?
Well, he found a solution. So, got to
watch the uh the expert solution uh as
well as a one or two minute clip.
So, um when you're in ISMS uh jobs, you
need to address your audiences
appropriately. You need a different uh
language when you're talking to HR. You
need a different language when talking
to IT, etc., etc.
um know that you know um
also look at the past. If you've done
this for a couple years, you have so
much data. You have like probably dozens
or hundreds of risk in your risk
register. Some that have been uh closed
off uh have been done away with. Use
that data to evaluate whether or not um
the classification was appropriate. you
know, like your end result might be,
well, we have a 5x5 risk matrix. Um, it
clusters around the uh the middle
section. We can do away with at least
one column, one uh one line.
So, um just use whatever data you
collected over the years to uh to
improve. And also important when you're
working in uh such a field you get
contact with lots and lots of things
that um are supposed to happen like
strategy from management uh projects
that haven't been announced yet. Uh you
uh get uh contact with individual
projects that they might not know about
each other. So use that insight to help
those people get their job done better.
tell them, okay, you should talk to that
project over there with that person
because he solved uh the problem that
you're working on already. So, um and of
course there's times when you can't
because you know it's something that's
still under uh um uh that's under you
know NDA or something but you know if
appropriate do that. So, and for
everybody else, when you're interacting
with uh people from an ISMS,
um don't expect too much of an IT
knowledge. You know, you might be lucky
uh you might have some people there,
cherish those, especially in larger
organizations when like the ISMs team
might be like 30 50 people. If you know
like the two or three maybe that have IT
skills, you need to connect with them
because they are your entry door into
the whole ISMS organization. If you need
to get something done,
they are your entry door. Um give
feedback, you know, they they're all
just doing their job. Um and also and
that's uh sort of what I uh um have been
uh trying to do is get people that know
it to get into ISMS, get into security
management. Um but I would only
recommend that to people who can put up
with documentation work, who can put up
with dealing with people that don't know
too much about it or whatever. So be uh
you have to have a certain level of
patience etc. And um but if if that fits
you, go into that because you have uh
lots of insights into your organization.
You have uh you build up a lot of
knowledge about uh surrounding like uh
legal uh stuff. You know, you just find
yourself, let me read through that law,
let me go talk to our corporate lawyer,
whatever. You learn stuff that you
didn't expect. And also career-wise,
that's you know, not a smart move.
Security is in demand. So
um that was it. I am just on time. So
now we're on to uh questions.
[Applause]
>> Yes, question.
Thanks for your talk. Um would you agree
in regards to ISO standards that there
should be more safeguards into them to
make sure that people don't scoot them
like make them easy to get etc. Um well
the the whole story is that the uh
especially the ISO 2701
they have an annex which contains uh
technical uh or pro procedural also
requirements. So uh things like you need
to do patch management you know so more
specific things uh you need to do access
control you need to have a concept etc.
Um so the picture I painted isn't the
whole picture but it's still a um just
an uh an overarching uh uh uh standard
because it has to be suitable for small
medium enterprises to you know uh the
largest uh organizations that we have on
earth. So, um I think it it's it's
already at where it should be. What I
really think where they should improve
is um the the auditors um because they
essentially you know what they their
idea is well you have an auditor who can
assess whatever is written in the those
standards. He's a auditor, right? That's
only half the story, you know. Um, a
good auditor will be like, "Okay, well,
you just told me this yesterday in our
audit session. I heard this from a
different team, whatever. How does that
map, you know?" Um, and th those are
things when uh, you know, especially if
that comes out to be an issue where
you're like, "Oh, wow." You know, yes.
Um, where you can really improve. So I
would say it's more the auditors that
are the uh where you where improvement
needs to happen and that's what I sort
of like about the uh the German baseline
protection center is because it has a
lot more of those the detailed technical
requirements
but as well as there you have auditors
who will be like do you have that can
you show me yes I'll show you a document
can you show me on the system we'll put
up something on the screen they'll be
like okay yeah and you're like we I
haven't even reached the screen where
that setting is you know so
yeah
>> yeah thank you very much for the talk um
could you briefly sketch the steps which
are necessary to become an auditor for
instance uh with regard to Wi-Fi
security
>> okay um
the the the
so there's Like auditor is a broad
class, right? Is someone who you
essentially pay to assess something. The
question is assessing against what
baseline against what standard? Um and
um when you're talking about like Wi-Fi,
it I I was I would be more thinking
about something like a pentest, you
know, so hey, just you know, pentest our
uh Wi-Fi. Um
so um essentially the um the the audits
that in terms of audit which is almost
always like um first
um check how it's supposed to be done.
So documents what are the process what
are the the security levels security
settings that are supposed to set and
then check the implementation is that
also the case um and um essentially like
the the standards there's um uh now
improving number of legal uh uh uh like
laws where uh things that have to be
audited against like the um the critical
infrastructure. So uh NIS 2 well if
there is a NIS 2 there's a NIS one NIS
one is about critical infrastructure in
uh Europe. So uh I think the the the
baseline was uh if you're providing
services out of some categories like
telecommunications water food etc. And
if you're serving more than 500,000
people your critical infrastructure and
then you need to uh have uh like I think
it's annual audits. So those are
auditors who test against the the legal
uh um uh requirements, right? Um so the
the question is really about what
setting would be a setting where you
test against specifically for Wi-Fi and
the only thing I can think of right now
is uh if uh um uh if it's a product and
that product um is the manage says okay
we need to get a common criteria
certification because common criteria is
a product certification so then you
could be an auditor for Wi-Fi or
whatever you know and um do that. Um
essentially uh it comes down to um
independent of what you are you need to
um uh essentially um demonstrate
knowledge uh either because you have
been already working with them and they
say okay yeah we know you you're good uh
but you still have to do the uh some
sort of you know test or whatever
assessment um in order to comply with
their processes.
Um but most often it'll be something
like well do this training at the end of
the training you'll do this assessment
and uh then um you'll be an auditor and
then as an auditor you need to sign like
okay I will buy to whatever principles
the organization set forth etc. Uh I
will do like annual uh training to you
know keep my skills up to date etc. So
there's a a lot of side work that an
auditor uh needs to do sort of just like
any you know personal certification. So
um um and then um most often when you uh
get a a contract uh um from from some
company to do an audit, you also then
again have to sign a letter of
independence. Okay, I'm uh you know they
pay me but I'm independent and um uh
there's in real life the the order well
I cannot you ask well okay we have this
issue order says okay that's something
you need to work on and you're like well
what do you suggest and the auditor will
be like I can't suggest you because that
will be consulting and I'm not allowed
to consult you with uh how you do right
but you can um with most auditors you
can sort of play the question and answer
game if we do it that Okay. Would that
be good enough?
May. No. Well, if we do it that way,
yes. So, um they they know about their
double roll is essentially what I'm
saying.
Okay.
Hello. Yeah. Actually have some tips
from my own experience as a Dutch uh
company with around 10 people. Um about
the auditors I think in the Netherlands
at least uh there also quite some decent
ones but it depends a bit on their
organization because they have their own
um
guidelines sort of some are really like
uh religious on the letter
>> and others are more of in the spirit or
they see if you have this addressed
properly.
>> Yeah.
>> Uh even then they judge on that. And um
what I also recommend if you looking for
an internal auditor actually get an
external auditor independent for example
and use that one because they are
actively does external audits
>> because they know what the latest stuff
is with interpretation of certain rules
>> right
>> and also ask them for example um to keep
an eye out on the stuff you do which is
actually not required by the standard
because often you see people if they
have the requirements they make stuff
up. Uh you should fried what you do,
>> right?
>> But then they fried stuff or start doing
stuff because they think it's what's
needed.
>> Yeah.
>> Um and then you get that the internal
auditor which asks like, well, where
does it say that you have to do that,
>> right?
>> And then you can cut the crap from your
ISMS as well.
>> And um yeah, and involve a lot of
people. I think that we for us uh we
pull in the team members who are uh in
their if their stuff is being audited we
always pull in the person who actually
does the work
>> and all the processes we have are
actually the ISMS processes is only very
separate a small part is only EMS only
the rest is all the the EMS basically
all the company documentation
>> and um yeah keep it simple
>> I think it's really Uh the ESO is
actually really easy if you did it a few
times and have it on the writt and then
>> um if you do some other certifications
and it's pretty easy.
>> Yeah. Yeah. No, especially the ISO 2701
if you have a a corporate setup uh where
can you effectively do work and just
like you said if you have done this a
few times
a oneerson show can can run the show. um
you want a backup, right? Um so you want
someone to to go along, but you don't
need five people in in that domain. Um
yes, that's a stressy job then, but it's
possible. And uh why am I saying that?
Because that's what I'm currently doing.
Then I want to thank you again for
having great making this great talk and
thank you for the great questions. Give
it up once again for Jurgen.
>> Thank you. And then enjoy the rest of
the camp.