5 steps to create a data flow map
As part of your GDPR (General Data Protection Regulation) compliance project, you must be able to understand what personal data you process. Specifically, Article 30 states that you must “maintain a record of processing activities under responsibility”. To achieve this, organisations must create a data flow map. This shows the flow ... Read More
How long does an ISO 27001 risk assessment take?
Completing a risk assessment is often the most complex and difficult aspect of an ISO 27001 project. Whatever tool you decide to use in your project, it needs to take into account many elements, such as assets, threats, vulnerabilities and controls, and the likelihood and impact values of those threats ... Read More
ISO 27001 risk assessments: The problem with using spreadsheets
An ISO 27001 risk assessment is at the core of your organisation’s information security management system (ISMS). Those new to tackling this complex step may rely on using a manual, inexpensive solution such as spreadsheets, but there are many disadvantages to doing so. Why using spreadsheets for your risk assessment ... Read More

