article thumbnail

Measure Security Performance, Not Policy Compliance

The Falcon's View

I'm convinced the answer to this query lies in stretching the "security as code" notion a step further by focusing on security performance metrics for everything and everyone instead of security policies. Applied, this approach scales very nicely across the organization. But I have digressed.

article thumbnail

NBlog Aug 23 - ISMS comms plan

Notice Bored

ISO/IEC 27003 offers examples of the things that should be communicated: Information security policies and procedures, plus changes thereto; [The organisation's] Information [risk and] security objectives; Knowledge on information security risks; Requirements [of information] suppliers; Feedback on the information security performance (not least the (..)