22 Mar Government The New NIST Secure Software Development Framework: Why It’s So Important for the USG Supply Chain March 22, 2022 By John Verry 0 comments Based on hard lessons learned from the SolarWinds attack plus “smell the coffee” guidance like the Bi...Continue reading
10 Mar ISO 27001 Certification Microsoft Just Endorsed ISO 27001 (and ISO 27701) Over SOC 2! Here’s What It Means to You March 10, 2022 By John Verry 2 comments As a longtime fan of ISO 27001 and its new privacy extension ISO 27701, I found this recent a...Continue reading
03 Mar Government New False Claims Act Initiative Could Increase Federal Contractors’ Cyber Compliance Risk March 3, 2022 By John Verry 0 comments All federal contractors and grant recipients need to be aware of the new Civil Cyber-Fraud Initiative...Continue reading
03 Mar Ethical Hacking It’s Hard to Spell Security with API (Translation: You Need an AppSec Strategy) March 3, 2022 By John Verry 0 comments The rapid growth of APIs has led to significant security risks. Unless you have been marooned on an u...Continue reading
24 Jan ISMS Consulting How (Not) to Perfect Your ISO 27001 Information Security Management System in Only 3 Years January 24, 2022 By John Verry 0 comments When Pivot Point Security decided to pursue ISO 27001 certification in 2015, we assumed it wo...Continue reading