ISO 27001 - What Is It Anyway?
May 04, 2016•42 min
Episode description
Description: As the new CIO at Steptoe & Johnson PLLC, Mark Combs sought to better understand the ISO 27001 standards to determine if he should pitch it to firm management, and if he would find value from instituting these standards at his firm. He wondered if peers in other firms were asking the same questions. We set up an interview with John Verry from Pivot Point Security so Mark could quiz the expert about ISO 27001 and get many of his (and your) questions answered. Some of the topics addressed include:
- What is ISO 27001 anyway - what does it mean and why do I want to do this?
- What standards must be met to become certified?
- Who is involved?
- How much time should a firm commit to gaining certification?
- Will ISO 27001 certification impact client matters?
- What are some of the common difficulties faced - where do certification seekers often fall short?
- How should someone new to the process estimate the total cost of certification?
- Is there an example of the standards preventing a breach?
For the best experience, listen in Metacast app for iOS or Android
