Canada Gets a National AI Strategy: Here's What It Changes
On June 3, 2026, Canada published its first National AI Strategy, AI for All. I read the document so you don't have to.
Your reference library — practical advice, news and analysis on information security and compliance.
On June 3, 2026, Canada published its first National AI Strategy, AI for All. I read the document so you don't have to.
A communications colleague called me on a Friday, panicked: an active ad was no longer promoting what it was supposed to promote.
At a manufacturing SMB, three developers were building an impressive inventory app. My question: how is the code validated before each release?
The question comes up in almost every Bill 25 compliance engagement I take on.
I came across a Hacker News article this week referencing the SOC-CMM 2026 Maturity Report, an annual study of about 200 SOCs worldwide.
Bruce Schneier recommends reading Melissa Hathaway's analysis in the Cyber Defense Review on his blog.
Since I've been using Claude, I always wonder which model to choose and what effort level to give it: medium, high, or xhigh? Here's what I've found.
Here is a scenario I have seen play out several times. A security incident occurs in an organization.
If you have received or conducted an audit by videoconference, this standard concerns you directly.
Anthropic has just published the first Project Glasswing data, and if you work in cybersecurity or compliance, here's what it means concretely for your…
Trust in a world where abuse seems to reign. Four years ago, I wrote an article on how to trust an auditor's report.
I continue in the same vein as my article on ISO 27001 controls that do not apply to organizations without software development.
Four years ago, I wrote an article on how to trust an auditor's report. I asked: how do you assess the auditor's independence, competence, and rigour?
You think your systems are well protected. Firewall in place, antivirus up to date, password policies respected.
I decided to take on this project to get back into programmer mode during the holiday break.
ISO 19011 was published in May 2026. If you read my article on the 2018 version, here I cover the new edition.
We all receive emails with links. Sometimes we are certain they are legitimate based on past trust; other times we hesitate.
I came across this Fortune article published in August 2025, which reports the results of an MIT study titled GenAI Divide: State of AI in Business 2025.
I'll give you the answer right away: yes.
When artificial intelligence comes up in an executive meeting, the image most people form in their minds is ChatGPT. A chat window, a question, an answer.
A Type 0 SMS arrives on your phone. You hear nothing. Nothing displays.
I've worked in cybersecurity for years. I know what ends up on the dark web. Your name, email, password, phone number, maybe your Social Insurance Number.
A client recently asked me whether their ISO 27001 certification was enough to meet Bill 25 requirements. My short answer: no.
A client called me a few months ago. He'd bought an ISO 27001 template pack online. Proud of himself. Six months of work filling in documents.
I cannot resist quoting one of my favourite books and films, but in this case the reference is not gratuitous.
Lately we've been seeing a new expression: vibe coding.
Today I present improvements to the tool at https://loi25.certi360.com. Each test checks one aspect of the site's behaviour regarding cookies and consent.
Today I'd like to share my opinion on compliance tools and platforms.
In the context of Quebec’s Act 25 on the protection of personal information, the security of communications between a website and its visitors is a basic…
It's a question that comes up often.
A good Business Continuity Plan (BCP) should not gather dust in the IT department's office.
It's done — the ISO/IEC 27701:2025 standard has finally been published.
After my latest ISO 27001 audits, I see the same mistake. Companies that declare applicable controls that have nothing to do with their reality.
First of all, it’s important to know that Le Top 10 is an awareness document that explains the main application risks, making it perfect for education,…
Even a simple website often relies on complex platforms, such as CMS (content management systems) or APIs. Safety must no longer be an afterthought.
It is a quality management standard that structures the way an organization operates, documents its processes and demonstrates compliance.
I’ve already talked about the ICI standard – March 2022 article: /en/iso-27018-privacy-protection-for-cloud-processors/
For those who have implemented ISO 27001:2022, you must create a file called a Statement of Applicability based on the Annex A controls.
Those who have implemented ISO27001:2022 must create a file called a “declaration of applicability” based on the controls in Annex A.
When it comes to business continuity in cybersecurity, most SMEs immediately think of backups or a redundant cloud server.
A Root Cause Analysis (RCA) is a structured approach to identifying the root causes of an incident or non-conformance in an exhaustive and precise manner.
ISO 22301:2019 is entitled “Security and resilience – Business continuity management systems – Requirements”.
My former company, Gardien Virtuel, used to do this type of testing, and I had so much fun carrying out these mandates, because with each project, there…
Over the past few days, I’ve seen a lot of comments on LinkedIn around words like “cybersecurity”, “information security” and “cyberattack”.
Every year, millions of our tax dollars are sent directly to US multinationals for software licenses.
Today I’d like to talk to you about the families of the ISO standard with a concrete example.
Achieving ISO 27001 certification is an important and stressful process for organizations wishing to demonstrate their commitment to information security.
Getting started with the International Organization for Standardization (ISO) It all began with ISO (International Organization for Standardization), an…
ISO/IEC 27001:2022 describes the requirements for implementing an Information Security Management System (ISMS).
When we think of information security, we often think of encryption, firewalls or access management.
This sample privacy policy is the basis on which I develop privacy policies for my clients’ websites.
The security measure in Annex A8.29 of ISO 27001:2022 is entitled “Security testing in development and acceptance”.
As part of my work on the implementation of ISO27001:2022, I have had to deal with issues relating to application development and testing, mainly for the…
The importance of IT security and the growing value of data in the business world have led to the creation of specific roles to manage and protect the…
The management of event logs is an essential aspect of the protection of personal information, particularly in the context of Quebec’s Bill 25.
Lately, I’ve been working on a number of mandates that, to my great delight, include the management of personal information, especially since the adoption…
PCI-DSS (Payment Card Industry Data Security Standard) certification is a set of security standards designed to ensure that all companies that process,…
What is an event log? An event log, also known as an audit trail or log, is a record that documents actions taken by computer systems, applications and…
Imagine an e-commerce company with annual sales of $20 million having its operations interrupted for 72 hours by a phishing e-mail.
Even the best-designed safety programs run into discrepancies. What to do in these situations?
As in other fields, in the world of information security, standing still is tantamount to going backwards!
This year, I’ve been lucky enough to read quite a few books that have made an impression on me.
Clause 9.3 of ISO 27001:2022 explains how to carry out a management review, which is an important step in ensuring that the Information Security…
ISO 27001 is an international standard that sets out the requirements for an information security management system (ISMS).
Clause 9.2 of ISO 27001:2022 requires organizations to carry out regular internal audits of their information security management system (ISMS).
Clause 9.1 of ISO27001:2022 requires organizations to carry out practical monitoring of their information security management system (ISMS).
It’s a Friday night, you’re chatting on a dating site and your suitor would like to meet you. What research should you do before meeting him?
How do you know that the team has mastered the business continuity or incident management plan?
Oh no! What bad news, to realize that your phone has been stolen. It’s so frustrating and worrying, especially at your age, knowing that your phone is an…
Clause 8.3 of ISO 27001:2022 is crucial because it addresses how organizations should respond to the information security risks identified in the risk…
The role of a Chief Information Security Officer (CISO) or the Information Systems Security Manager (ISSM) is a very important role for any organization,…
Clause 8.2 is one of the most important clauses in the standard, as it forms the basis for all other information security controls.
Clause 8.1 of ISO 27001 underlines the importance of rigorous planning and control of information security operations within an organization.
We all know that when we draw up our wills, we need to list our bank accounts, other financial institutions and assets that will be sold after our death,…
I come across a survey report on the subject of supply chain risk management from Gartner 2023.
An artifact is an element created as an output from a process or project.
Today we’re going to explore the difference between de-identified data and anonymized anonymized data.
When it comes to information security, every detail counts, including the way information is created, stored, maintained and destroyed.
This is the last article in my series on stalking. This behavior is very disturbing and destabilizing, especially with the use of artificial intelligence…
Here we are at that time of year when we pause and look back at all the work we’ve done, and in my case, I’m also looking back at all the books I’ve read…
The issue of security and digital privacy is paramount. As technology advances, it’s essential that we continue to be concerned about protecting our…
Today, I present the third article in a series on harassment. In this article, I seek to understand how to prevent harassment.
Following on from the previous article, in which I explored the laws surrounding stalking, allow me to present a few concrete examples that illustrate in…
On the night of Friday August 25 to Saturday August 26, 2023, Ianick Lamontagne committed an irreparable act: the murder of his children, followed by his…
Information security is a crucial issue in today’s digital age. Yet we often only realize its importance after we’ve been the victim of a cyber-attack or…
Clause 7.2 is designed to ensure that those who have an impact on the organization’s information security have the appropriate and necessary skills to…
The organization must identify and provide the resources needed to establish, implement, maintain and continuously improve the information security…
Planning changes to an information security management system (ISMS) is important for several reasons.
Setting a goal is the best way to achieve it, otherwise how do we know when we’ve succeeded?
It’s now almost a year since ISO 27001:2013 was replaced by the new version named ISO 27001:2022. Here’s your transition plan! Change – Photo by Suzanne D.
Information security risk management is the set of actions taken by an organization to understand and reduce the effects of risk.
Roles, responsibilities and power sharing within an organization are of the utmost importance when it comes to information security.
Policy is the equivalent of a corporate mission, since without a mission there is no corporate project.
Photo by Brooke Lark on Unsplash The organization’s management is key to ensuring that ISO 27001 requirements are met and that the ISMS is effective.
Clause 4.4 of the ISO27001 standard is one of the smallest in size, but the one that, in my opinion, has the greatest day-to-day impact on the organization.
The scope of an ISMS (Information Security Management System) is crucial, as it defines the direction and objective that the security team must follow.
As we often say, information security is everybody’s business. We need to identify and understand the needs of this world.
To begin with, are we able to define who the organization is in clear terms?
Photo by Possessed Photography on Unsplash When implementing a management system (such as SGSI-ISO27001) we need to understand the difference between…
Photo by Glenn Carstens-Peters on Unsplash Becoming an ISO 27001 external auditor requires a combination of training, professional experience and…
Photo by Ashim D’Silva on Unsplash You may have been discovering this slowly over the last few years as you’ve read me talking about books, but I really…
The question of the cost of an ISO27001 certification project frequently comes up, and rightly so, since this certification is based on the most widely…
Cloud computing is becoming increasingly popular as companies look for ways to improve efficiency and reduce costs. Security in this context is essential.
In a world of compliance with laws, regulations and standards, it can be difficult to know whether or not to trust an auditor’s report.
When I received notification of the standard’s publication on March 31, 2022, I thought it was an April fool’s joke.
Are you a cloud service provider? Do your customers process personal information? Do your customers use your platform to deliver their services?
A few days ago I asked a question on the LinkedIn platform, namely what would be the best choice for a password vault application.
There are two distinct roles when it comes to corporate responsibility for managing personal information.
A communication plan is a formal document that describes how information will be shared between the organization and its stakeholders, both internal and…
Lately, I’ve been doing a lot of compliance audits (internal and external), mainly for PCIDSS and ISO standards.
On February 15, 2022, a revision of the ISO/IEC 27002 standard is published and available to all.
During this festive period of exchange and discussion about our mental health, I’d like to bring you a subject that isn’t often discussed in the auditing…
What you need to know to manage a minimal information security program in a corporate context.
Do your customers pay you with their credit cards? Then the PCI DSS standard is for you!
We’re in the first year of a three-year implementation period. Here’s what you need to know about this first year!
Your company provides services to its customers? and your customers ask you for a SOC 2 type 2 report?
ISO/IEC 27001 formally defines an information security management system (ISMS) as a set of activities designed to manage information security risks.
When a cybersecurity incident occurs, it’s important to record all the details so you can remember it and prevent it from happening again.
Here we are again, in a period of confinement due to Covid-19. I thought it was time to evaluate its telecommuting policies.
Source: Flikr.com Here we are again at the end of the year, and the confinement and sanitary measures have only increased my love of reading, which I must…
In the course of my work, I come across all kinds of companies, but too many have no procedures or methods for managing incidents.
No articles match your search.