<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Certi360 Blog</title>
    <link>https://certi360.com/</link>
    <description>Cybersecurity, ISO 27001 and Bill 25 insights for Quebec SMBs</description>
    <language>en-CA</language>
    <lastBuildDate>Thu, 02 Jul 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://certi360.com/en/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Personal Information Inventory: What Exactly Should You List?</title>
      <link>https://certi360.com/en/personal-information-inventory-what-exactly-should-you-list/</link>
      <guid isPermaLink="true">https://certi360.com/en/personal-information-inventory-what-exactly-should-you-list/</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>The question comes up in almost every Bill 25 compliance engagement I take on.</description>
    </item>
    <item>
      <title>Which Claude Model to Choose — and at What Effort Level?</title>
      <link>https://certi360.com/en/which-claude-model-to-choose-and-at-what-effort-level/</link>
      <guid isPermaLink="true">https://certi360.com/en/which-claude-model-to-choose-and-at-what-effort-level/</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <description>Since I&apos;ve been using Claude, I always wonder which model to choose and what effort level to give it: medium, high, or xhigh? Here&apos;s what I&apos;ve found.</description>
    </item>
    <item>
      <title>ISO/IEC 27043: The Backbone of Digital Investigations</title>
      <link>https://certi360.com/en/iso-iec-27043-the-backbone-of-digital-investigations/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-iec-27043-the-backbone-of-digital-investigations/</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
      <description>Here is a scenario I have seen play out several times. A security incident occurs in an organization. The internal team (or an external consultant) starts digging through systems: someone collects event logs, another takes screenshots, a third tries to reconstruct the sequence of events.</description>
    </item>
    <item>
      <title>ISO/IEC TS 17012:2024: The Official Guide for Remote Audits</title>
      <link>https://certi360.com/en/iso-iec-ts-170122024-official-guide-for-remote-audits/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-iec-ts-170122024-official-guide-for-remote-audits/</guid>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <description>If you have received or conducted an audit by videoconference, this standard concerns you directly. ISO/IEC TS 17012:2024 is the first international technical specification devoted exclusively to remote audit methods in management systems. Published July 2024; ISO 19011:2026 refers to it.</description>
    </item>
    <item>
      <title>The Exposure Window Has Become a Catastrophe Window</title>
      <link>https://certi360.com/en/the-exposure-window-has-become-a-catastrophe-window/</link>
      <guid isPermaLink="true">https://certi360.com/en/the-exposure-window-has-become-a-catastrophe-window/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>Anthropic has just published the first Project Glasswing data, and if you work in cybersecurity or compliance, here&apos;s what it means concretely for your organization.</description>
    </item>
    <item>
      <title>What Increases and Decreases Trust in SOC 2 and ISO 27001</title>
      <link>https://certi360.com/en/what-increases-and-decreases-trust-in-soc-2-and-iso-27001/</link>
      <guid isPermaLink="true">https://certi360.com/en/what-increases-and-decreases-trust-in-soc-2-and-iso-27001/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>Trust in a world where abuse seems to reign. Four years ago, I wrote an article on how to trust an auditor&apos;s report. I asked: how do you assess an auditor&apos;s independence, competence, and rigour? The problem was already real. In 2026, it has become industrialized.</description>
    </item>
    <item>
      <title>AI in the SOC: Why 90% of Teams Get No Real Value</title>
      <link>https://certi360.com/en/ai-in-the-soc-why-90-percent-of-teams-get-no-real-value/</link>
      <guid isPermaLink="true">https://certi360.com/en/ai-in-the-soc-why-90-percent-of-teams-get-no-real-value/</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
      <description>I came across a Hacker News article this week referencing the SOC-CMM 2026 Maturity Report, an annual study of about 200 SOCs worldwide. The number that stopped me: only 10% of SOCs report excellent value from their AI deployments.</description>
    </item>
    <item>
      <title>ISO 42001: Your SMB Only Uses ChatGPT? Here Are the Controls That Do Not Apply</title>
      <link>https://certi360.com/en/iso-42001-your-smb-only-uses-chatgpt-non-applicable-controls/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-42001-your-smb-only-uses-chatgpt-non-applicable-controls/</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
      <description>I continue in the same vein as my article on ISO 27001 controls that do not apply to organizations without software development. Today I tackle the AI version. ISO/IEC 42001:2023, published in December 2023, governs artificial intelligence management systems.</description>
    </item>
    <item>
      <title>Trust in a World Where Abuse Seems to Reign</title>
      <link>https://certi360.com/en/trust-in-a-world-where-abuse-seems-to-reign/</link>
      <guid isPermaLink="true">https://certi360.com/en/trust-in-a-world-where-abuse-seems-to-reign/</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
      <description>Four years ago, I wrote an article on how to trust an auditor&apos;s report. I asked: how do you assess the auditor&apos;s independence, competence, and rigour? The problem was already real. In 2026, it has been industrialized.</description>
    </item>
    <item>
      <title>The Basement Hacker Never Sleeps</title>
      <link>https://certi360.com/en/the-basement-hacker-never-sleeps/</link>
      <guid isPermaLink="true">https://certi360.com/en/the-basement-hacker-never-sleeps/</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <description>Bruce Schneier recommends reading Melissa Hathaway&apos;s analysis in the Cyber Defense Review on his blog.</description>
    </item>
    <item>
      <title>Your Vendors Are a Target — ISO 27001 Planned for It</title>
      <link>https://certi360.com/en/your-vendors-are-a-target-iso-27001-planned-for-it/</link>
      <guid isPermaLink="true">https://certi360.com/en/your-vendors-are-a-target-iso-27001-planned-for-it/</guid>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <description>You think your systems are well protected. Firewall in place, antivirus up to date, password policies respected. And yet, an attacker gets into your network… through your accounting software vendor.</description>
    </item>
    <item>
      <title>Bill 25 Project to Help You Understand Your Website&apos;s Compliance. Free!</title>
      <link>https://certi360.com/en/bill-25-project-understand-your-website-compliance-free/</link>
      <guid isPermaLink="true">https://certi360.com/en/bill-25-project-understand-your-website-compliance-free/</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <description>I decided to take on this project to get back into programmer mode during the holiday break. Coding for real — meaning without eating, sleeping, knowing what day it is, or taking a shower! I have a lot of admiration for those who do it for a living. Here is the result: loi25.certi360.com.</description>
    </item>
    <item>
      <title>ISO 19011:2026 — What Changes</title>
      <link>https://certi360.com/en/iso-190112026-what-changes/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-190112026-what-changes/</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <description>ISO 19011 was published in May 2026. If you read my article on the 2018 version, here I cover the new edition. The structure remains the same: audit principles, audit programme, conduct, auditor competence. What changes is the content within those chapters.</description>
    </item>
    <item>
      <title>I Got a Link by Email. How Do I Know If It&apos;s Safe to Click?</title>
      <link>https://certi360.com/en/how-to-tell-if-an-email-link-is-safe-to-click/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-to-tell-if-an-email-link-is-safe-to-click/</guid>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <description>We all receive emails with links. Sometimes we are certain they are legitimate based on past trust; other times we hesitate. That hesitation is healthy, because malicious links are today the primary entry point for attacks. Here is how to verify a link before clicking.</description>
    </item>
    <item>
      <title>95% of AI Projects Fail — Stay on Track and Measure Value Added</title>
      <link>https://certi360.com/en/95-percent-of-ai-projects-fail-measure-the-value-added/</link>
      <guid isPermaLink="true">https://certi360.com/en/95-percent-of-ai-projects-fail-measure-the-value-added/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <description>I came across this Fortune article published in August 2025, which reports the results of an MIT study titled GenAI Divide: State of AI in Business 2025. The statistic struck me.</description>
    </item>
    <item>
      <title>AI Agents and Prompt Injection: Can a Simple Email Steal Your Data? Yes.</title>
      <link>https://certi360.com/en/ai-agents-and-prompt-injection-can-a-simple-email-steal-your-data/</link>
      <guid isPermaLink="true">https://certi360.com/en/ai-agents-and-prompt-injection-can-a-simple-email-steal-your-data/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <description>I&apos;ll give you the answer right away: yes.</description>
    </item>
    <item>
      <title>Fear and Trust in AI: People Only See the Chat — But What Is the Rest?</title>
      <link>https://certi360.com/en/fear-and-trust-in-ai-people-only-see-the-chat/</link>
      <guid isPermaLink="true">https://certi360.com/en/fear-and-trust-in-ai-people-only-see-the-chat/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <description>When artificial intelligence comes up in an executive meeting, the image most people form in their minds is ChatGPT. A chat window, a question, an answer.</description>
    </item>
    <item>
      <title>Silent SMS — Type 0: Your Phone Responds to Someone You Never See</title>
      <link>https://certi360.com/en/silent-sms-type-0-your-phone-responds-to-someone-you-never-see/</link>
      <guid isPermaLink="true">https://certi360.com/en/silent-sms-type-0-your-phone-responds-to-someone-you-never-see/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>A Type 0 SMS arrives on your phone. You hear nothing. Nothing displays. Yet your phone received the message and automatically responded — without notifying you or asking permission.</description>
    </item>
    <item>
      <title>Privacy: Even Wounded, It&apos;s Worth Fighting For</title>
      <link>https://certi360.com/en/privacy-even-wounded-it-is-worth-fighting-for/</link>
      <guid isPermaLink="true">https://certi360.com/en/privacy-even-wounded-it-is-worth-fighting-for/</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <description>I&apos;ve worked in cybersecurity for years. I know what ends up on the dark web. Your name, email, password, phone number, maybe your Social Insurance Number. Breaches pile up: LinkedIn, Desjardins, Facebook, Equifax. At some point, you think: what&apos;s the point?</description>
    </item>
    <item>
      <title>ISO/IEC 27701 — Do You Really Manage Your Clients&apos; Personal Information?</title>
      <link>https://certi360.com/en/iso-iec-27701-do-you-really-manage-clients-personal-information/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-iec-27701-do-you-really-manage-clients-personal-information/</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
      <description>A client recently asked me whether their ISO 27001 certification was enough to meet Bill 25 requirements. My short answer: no. ISO 27001 protects information. ISO/IEC 27701 protects personal information. If your organization handles personal information, this standard concerns you.</description>
    </item>
    <item>
      <title>Can You &quot;Pass&quot; ISO 27001 With Templates (or AI)?</title>
      <link>https://certi360.com/en/can-you-pass-iso-27001-with-templates-or-ai/</link>
      <guid isPermaLink="true">https://certi360.com/en/can-you-pass-iso-27001-with-templates-or-ai/</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <description>A client called me a few months ago. He&apos;d bought an ISO 27001 template pack online. Proud of himself. Six months of work filling in documents. I ended up at his office for the preparatory internal audit.</description>
    </item>
    <item>
      <title>ISO 19011 — The Standard to Rule Them All in Compliance</title>
      <link>https://certi360.com/en/iso-19011-the-standard-to-rule-them-all-in-compliance/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-19011-the-standard-to-rule-them-all-in-compliance/</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <description>I cannot resist quoting one of my favourite books and films, but in this case the reference is not gratuitous. A standard to rule them all is exactly what ISO 19011 is. If you have ever received a compliance audit report — ISO 27001, ISO 9001, ISO 22301 — that report followed a precise logic.</description>
    </item>
    <item>
      <title>Why Vibe Coding Is So Polarizing</title>
      <link>https://certi360.com/en/why-vibe-coding-is-so-polarizing/</link>
      <guid isPermaLink="true">https://certi360.com/en/why-vibe-coding-is-so-polarizing/</guid>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <description>Lately we&apos;ve been seeing a new expression: vibe coding.</description>
    </item>
    <item>
      <title>Version 1.2.1 – Improved Cookie Analysis</title>
      <link>https://certi360.com/en/version-1-21-improved-cookie-analysis/</link>
      <guid isPermaLink="true">https://certi360.com/en/version-1-21-improved-cookie-analysis/</guid>
      <pubDate>Sat, 07 Feb 2026 00:00:00 GMT</pubDate>
      <description>Today I present improvements to the tool at https://loi25.certi360.com. Each test checks one aspect of the site&apos;s behaviour regarding cookies and consent. 1. CONSENT COMPLIANCE 2. COOKIE SECURITY 3. RETENTION PERIODS 4. DARK PATTERNS IN THE BANNER</description>
    </item>
    <item>
      <title>Opinion — Compliance Platforms</title>
      <link>https://certi360.com/en/opinion-compliance-platforms/</link>
      <guid isPermaLink="true">https://certi360.com/en/opinion-compliance-platforms/</guid>
      <pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate>
      <description>Today I&apos;d like to share my opinion on compliance tools and platforms.</description>
    </item>
    <item>
      <title>Does My Site Really Need a Consent Banner?</title>
      <link>https://certi360.com/en/does-my-site-really-need-a-consent-banner/</link>
      <guid isPermaLink="true">https://certi360.com/en/does-my-site-really-need-a-consent-banner/</guid>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
      <description>It&apos;s a question that comes up often.</description>
    </item>
    <item>
      <title>Understanding TLS/SSL testing on Loi25.certi360.com</title>
      <link>https://certi360.com/en/understanding-tls-ssl-testing-on-loi25-certi360-com/</link>
      <guid isPermaLink="true">https://certi360.com/en/understanding-tls-ssl-testing-on-loi25-certi360-com/</guid>
      <pubDate>Mon, 29 Dec 2025 00:00:00 GMT</pubDate>
      <description>In the context of Quebec’s Act 25 on the protection of personal information, the security of communications between a website and its visitors is a basic protection measure. When an organization collects or transmits personal information via its Web site, it must ensure that these exchanges are prot</description>
    </item>
    <item>
      <title>84 Audit Questions to Evaluate a Business Continuity Plan</title>
      <link>https://certi360.com/en/84-audit-questions-to-evaluate-a-business-continuity-plan/</link>
      <guid isPermaLink="true">https://certi360.com/en/84-audit-questions-to-evaluate-a-business-continuity-plan/</guid>
      <pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate>
      <description>A good Business Continuity Plan (BCP) should not gather dust in the IT department&apos;s office.</description>
    </item>
    <item>
      <title>New ISO/IEC 27701:2025 Standard</title>
      <link>https://certi360.com/en/new-iso-iec-27701-2025-standard/</link>
      <guid isPermaLink="true">https://certi360.com/en/new-iso-iec-27701-2025-standard/</guid>
      <pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate>
      <description>It&apos;s done — the ISO/IEC 27701:2025 standard has finally been published.</description>
    </item>
    <item>
      <title>ISO27001 – No software development, here is the list of non-applicable controls</title>
      <link>https://certi360.com/en/iso27001-no-software-development-here-is-the-list-of-non-applicable-controls/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-no-software-development-here-is-the-list-of-non-applicable-controls/</guid>
      <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
      <description>After my latest ISO 27001 audits, I see the same mistake. Companies that declare applicable controls that have nothing to do with their reality. They complicate their lives, waste time and spend money unnecessarily. Software dev – Photo by Ajay Gorecha on Unsplash In the worst case, a financial serv</description>
    </item>
    <item>
      <title>Difference between OWASP TOP10 and ASVS</title>
      <link>https://certi360.com/en/difference-between-owasp-top10-and-asvs/</link>
      <guid isPermaLink="true">https://certi360.com/en/difference-between-owasp-top10-and-asvs/</guid>
      <pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate>
      <description>First of all, it’s important to know that Le Top 10 is an awareness document that explains the main application risks, making it perfect for education, rapid self-assessment and “quick wins”. On the other hand,ASVS is a comprehensive requirements framework for systematically building, testing and va</description>
    </item>
    <item>
      <title>OWASP ASVS – What is it?</title>
      <link>https://certi360.com/en/owasp-asvs-what-is-it/</link>
      <guid isPermaLink="true">https://certi360.com/en/owasp-asvs-what-is-it/</guid>
      <pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate>
      <description>Even a simple website often relies on complex platforms, such as CMS (content management systems) or APIs. Safety must no longer be an afterthought. It’s a basic requirement. The OWASP ASVS, Application Security Verification Standard, is a set of requirements for designing, developing, testing and c</description>
    </item>
    <item>
      <title>Introduction ISO 9001: Quality management!</title>
      <link>https://certi360.com/en/introduction-iso-9001-quality-management/</link>
      <guid isPermaLink="true">https://certi360.com/en/introduction-iso-9001-quality-management/</guid>
      <pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate>
      <description>It is a quality management standard that structures the way an organization operates, documents its processes and demonstrates compliance. ISO 9001 is not just for manufacturers who want to produce defect-free equipment. Usually, the standard is requested by a customer who wants to be sure of the st</description>
    </item>
    <item>
      <title>ISO/IEC 27018:2025 : New version for cloud processors</title>
      <link>https://certi360.com/en/iso-iec-270182025-new-version-for-cloud-processors/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-iec-270182025-new-version-for-cloud-processors/</guid>
      <pubDate>Fri, 29 Aug 2025 00:00:00 GMT</pubDate>
      <description>I’ve already talked about the ICI standard – March 2022 article: https://medium.com/@btk667/iso27018-concernant-la-protection-des-renseignements-personnels-des-processeurs-infonuagique-261378d7ddef ISO announced on August 25, 2025, the update of the ISO/IEC 27018 standard. I’d like to tell you what’</description>
    </item>
    <item>
      <title>Which ISO 27001 Controls Apply Under Quebec Bill 25?</title>
      <link>https://certi360.com/en/which-iso27001-controls-apply-under-quebec-bill-25/</link>
      <guid isPermaLink="true">https://certi360.com/en/which-iso27001-controls-apply-under-quebec-bill-25/</guid>
      <pubDate>Sun, 03 Aug 2025 00:00:00 GMT</pubDate>
      <description>For those who have implemented ISO 27001:2022, you must create a file called a Statement of Applicability based on the Annex A controls. There are 93 of them. You must also explain why certain controls apply to your organization.</description>
    </item>
    <item>
      <title>Which ISO27001 standards are applicable in accordance with Quebec’s Act 25 on…</title>
      <link>https://certi360.com/en/which-iso27001-standards-are-applicable-in-accordance-with-quebecs-act-25-on/</link>
      <guid isPermaLink="true">https://certi360.com/en/which-iso27001-standards-are-applicable-in-accordance-with-quebecs-act-25-on/</guid>
      <pubDate>Sun, 03 Aug 2025 00:00:00 GMT</pubDate>
      <description>Those who have implemented ISO27001:2022 must create a file called a “declaration of applicability” based on the controls in Annex A. There are 93 of them.We also need to explain why certain controls are applicable to our organization. The easy way is if there is a legal requirement, contractual req</description>
    </item>
    <item>
      <title>ISO27031:2025 – New version for IT continuity</title>
      <link>https://certi360.com/en/iso270312025-new-version-for-it-continuity/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso270312025-new-version-for-it-continuity/</guid>
      <pubDate>Fri, 25 Jul 2025 00:00:00 GMT</pubDate>
      <description>When it comes to business continuity in cybersecurity, most SMEs immediately think of backups or a redundant cloud server. Yet this is only the tip of the iceberg. The ISO/IEC 27031 standard has been in existence for over 10 years, providing a framework for the continuity of information and communic</description>
    </item>
    <item>
      <title>Correcting without looking for the cause is wrong!</title>
      <link>https://certi360.com/en/correcting-without-looking-for-the-cause-is-wrong/</link>
      <guid isPermaLink="true">https://certi360.com/en/correcting-without-looking-for-the-cause-is-wrong/</guid>
      <pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate>
      <description>A Root Cause Analysis (RCA) is a structured approach to identifying the root causes of an incident or non-conformance in an exhaustive and precise manner. I came across this image a few months ago during an internet search for a client and I’ve kept it ever since because I find it so simple, so I’d</description>
    </item>
    <item>
      <title>ISO 22301:2019 focuses on business continuity</title>
      <link>https://certi360.com/en/iso-223012019-focuses-on-business-continuity/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-223012019-focuses-on-business-continuity/</guid>
      <pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate>
      <description>ISO 22301:2019 is entitled “Security and resilience – Business continuity management systems – Requirements”. It is the international benchmark for implementing a continuity management system. It guides organizations in the planning, implementation and continuous improvement of processes designed to</description>
    </item>
    <item>
      <title>Physical intrusion testing?</title>
      <link>https://certi360.com/en/physical-intrusion-testing/</link>
      <guid isPermaLink="true">https://certi360.com/en/physical-intrusion-testing/</guid>
      <pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate>
      <description>My former company, Gardien Virtuel, used to do this type of testing, and I had so much fun carrying out these mandates, because with each project, there are extraordinary stories, anecdotes that make us understand just how vulnerable employees can be! Locked door – Photo by Sheldon Kennedy on Unspla</description>
    </item>
    <item>
      <title>Information security VS Cybersecurity</title>
      <link>https://certi360.com/en/information-security-vs-cybersecurity/</link>
      <guid isPermaLink="true">https://certi360.com/en/information-security-vs-cybersecurity/</guid>
      <pubDate>Sat, 21 Jun 2025 00:00:00 GMT</pubDate>
      <description>Over the past few days, I’ve seen a lot of comments on LinkedIn around words like “cybersecurity”, “information security” and “cyberattack”. In the media, it seems that every time a computer is involved, there’s always talk of a “cyber attack”, even when it’s a minor incident or not linked to a secu</description>
    </item>
    <item>
      <title>Opinion on open source software: Stop financing our technological dependence</title>
      <link>https://certi360.com/en/opinion-on-open-source-software-stop-financing-our-technological-dependence/</link>
      <guid isPermaLink="true">https://certi360.com/en/opinion-on-open-source-software-stop-financing-our-technological-dependence/</guid>
      <pubDate>Mon, 26 May 2025 00:00:00 GMT</pubDate>
      <description>Every year, millions of our tax dollars are sent directly to US multinationals for software licenses. This does not create jobs here, nor expertise or a basis for building other solutions. The only statistic I found was that in “2012, the Quebec government spent $1.4 billion renewing proprietary lic</description>
    </item>
    <item>
      <title>Consent standards, ISO 27560 and ISO 29184</title>
      <link>https://certi360.com/en/consent-standards-iso-27560-and-iso-29184/</link>
      <guid isPermaLink="true">https://certi360.com/en/consent-standards-iso-27560-and-iso-29184/</guid>
      <pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate>
      <description>Today I’d like to talk to you about the families of the ISO standard with a concrete example. I’ve just discovered that the ISO 27560 standard is free – take the opportunity to download it and let’s talk about these standards. ISO/IEC 27560 and ISO/IEC 29184 both deal with data protection consent, b</description>
    </item>
    <item>
      <title>ISO 27001 audits: Differences between Stage 1 and Stage 2</title>
      <link>https://certi360.com/en/iso-27001-audits-differences-between-stage-1-and-stage-2/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-audits-differences-between-stage-1-and-stage-2/</guid>
      <pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate>
      <description>Achieving ISO 27001 certification is an important and stressful process for organizations wishing to demonstrate their commitment to information security. The certification process towards ISO27001 comprises two key stages: stage 1 and stage 2 audits. dual – Photo by Possessed Photography on Unsplas</description>
    </item>
    <item>
      <title>Understand the role of ISO certification and accreditation bodies.</title>
      <link>https://certi360.com/en/understand-the-role-of-iso-certification-and-accreditation-bodies/</link>
      <guid isPermaLink="true">https://certi360.com/en/understand-the-role-of-iso-certification-and-accreditation-bodies/</guid>
      <pubDate>Wed, 09 Apr 2025 00:00:00 GMT</pubDate>
      <description>Getting started with the International Organization for Standardization (ISO) It all began with ISO (International Organization for Standardization), an international non-governmental organization founded in 1947. ISO develops and publishes “voluntary” international standards in a wide range of fiel</description>
    </item>
    <item>
      <title>ISO27001 – Defining the scope of the security program</title>
      <link>https://certi360.com/en/iso27001-defining-the-scope-of-the-security-program/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-defining-the-scope-of-the-security-program/</guid>
      <pubDate>Fri, 04 Apr 2025 00:00:00 GMT</pubDate>
      <description>ISO/IEC 27001:2022 describes the requirements for implementing an Information Security Management System (ISMS). One of the crucial steps in this process is the creation of a precise and clear definition the scope of ISMS. I’ve already talked about this subject here. Today, I’d like to focus on writ</description>
    </item>
    <item>
      <title>ISO 27001 – A.5.31- Legal, regulatory and contractual requirements</title>
      <link>https://certi360.com/en/iso-27001-a-5-31-legal-regulatory-and-contractual-requirements/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-a-5-31-legal-regulatory-and-contractual-requirements/</guid>
      <pubDate>Thu, 27 Mar 2025 00:00:00 GMT</pubDate>
      <description>When we think of information security, we often think of encryption, firewalls or access management. Yet one of the pitfalls of small business is ignoring legal, regulatory and contractual obligations. Law – Photo by Mikhail Pavstyuk on Unsplash Ignoring them can have costly consequences. For exampl</description>
    </item>
    <item>
      <title>Your privacy policy template</title>
      <link>https://certi360.com/en/your-privacy-policy-template/</link>
      <guid isPermaLink="true">https://certi360.com/en/your-privacy-policy-template/</guid>
      <pubDate>Tue, 18 Mar 2025 00:00:00 GMT</pubDate>
      <description>This sample privacy policy is the basis on which I develop privacy policies for my clients’ websites. Although it serves as a starting point, it must be adapted to the specific characteristics of each organization, taking into account its size, needs and sector of activity. It is also strongly recom</description>
    </item>
    <item>
      <title>ISO27001 – A8.29 with CI/CD pipeline – Continuous integration and continuous deployment</title>
      <link>https://certi360.com/en/iso27001-a8-29-with-ci-cd-pipeline-continuous-integration-and-continuous-deployment/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-a8-29-with-ci-cd-pipeline-continuous-integration-and-continuous-deployment/</guid>
      <pubDate>Tue, 11 Mar 2025 00:00:00 GMT</pubDate>
      <description>The security measure in Annex A8.29 of ISO 27001:2022 is entitled “Security testing in development and acceptance”. Organizations must define and implement security testing processes throughout the development lifecycle.. The aim is to identify and correct vulnerabilities before systems or applicati</description>
    </item>
    <item>
      <title>ISO27001 – A8.28 – DAST and SAST – Security and development tools</title>
      <link>https://certi360.com/en/iso27001-a8-28-dast-and-sast-security-and-development-tools/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-a8-28-dast-and-sast-security-and-development-tools/</guid>
      <pubDate>Thu, 06 Mar 2025 00:00:00 GMT</pubDate>
      <description>As part of my work on the implementation of ISO27001:2022, I have had to deal with issues relating to application development and testing, mainly for the security measure in Annex 8.28. Accept – Photo by Clay Banks on Unsplash Note that the development is covered by the following measures: 8.25– Sec</description>
    </item>
    <item>
      <title>What is the role of an information asset manager?</title>
      <link>https://certi360.com/en/what-is-the-role-of-an-information-asset-manager/</link>
      <guid isPermaLink="true">https://certi360.com/en/what-is-the-role-of-an-information-asset-manager/</guid>
      <pubDate>Mon, 17 Feb 2025 00:00:00 GMT</pubDate>
      <description>The importance of IT security and the growing value of data in the business world have led to the creation of specific roles to manage and protect the organization’s information assets. Among these roles, I’d like to mention here that of the information assets manager. In the course of my work I oft</description>
    </item>
    <item>
      <title>Event logs: Bill 25 and privacy explained</title>
      <link>https://certi360.com/en/event-logs-bill-25-and-privacy-explained/</link>
      <guid isPermaLink="true">https://certi360.com/en/event-logs-bill-25-and-privacy-explained/</guid>
      <pubDate>Wed, 05 Feb 2025 00:00:00 GMT</pubDate>
      <description>The management of event logs is an essential aspect of the protection of personal information, particularly in the context of Quebec’s Bill 25. These logs contain IP addresses, which are personal information. Server farm – Photo by Massimo Botturi on Unsplash In the event of negligent use of activit</description>
    </item>
    <item>
      <title>Cookies : Bill 25 and privacy explained</title>
      <link>https://certi360.com/en/cookies-bill-25-and-privacy-explained/</link>
      <guid isPermaLink="true">https://certi360.com/en/cookies-bill-25-and-privacy-explained/</guid>
      <pubDate>Sat, 01 Feb 2025 00:00:00 GMT</pubDate>
      <description>Lately, I’ve been working on a number of mandates that, to my great delight, include the management of personal information, especially since the adoption of Bill 25. The new law on personal information is motivating companies to take matters into their own hands. One of the issues at stake is the m</description>
    </item>
    <item>
      <title>20 myths about PCI-DSS</title>
      <link>https://certi360.com/en/20-myths-about-pci-dss/</link>
      <guid isPermaLink="true">https://certi360.com/en/20-myths-about-pci-dss/</guid>
      <pubDate>Mon, 27 Jan 2025 00:00:00 GMT</pubDate>
      <description>PCI-DSS (Payment Card Industry Data Security Standard) certification is a set of security standards designed to ensure that all companies that process, store or transmit credit card information maintain a secure environment. Credit Card – Photo by Mark OFlynn on Unsplash I’ve already told you about</description>
    </item>
    <item>
      <title>How long can I keep my system event logs?</title>
      <link>https://certi360.com/en/how-long-can-i-keep-my-system-event-logs/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-long-can-i-keep-my-system-event-logs/</guid>
      <pubDate>Wed, 22 Jan 2025 00:00:00 GMT</pubDate>
      <description>What is an event log? An event log, also known as an audit trail or log, is a record that documents actions taken by computer systems, applications and users. These logs are essential for IT security, troubleshooting, regulatory compliance and business monitoring. Archives – Photo by Galen Crout on</description>
    </item>
    <item>
      <title>Information security training: investment or false hope?</title>
      <link>https://certi360.com/en/information-security-training-investment-or-false-hope/</link>
      <guid isPermaLink="true">https://certi360.com/en/information-security-training-investment-or-false-hope/</guid>
      <pubDate>Fri, 10 Jan 2025 00:00:00 GMT</pubDate>
      <description>Imagine an e-commerce company with annual sales of $20 million having its operations interrupted for 72 hours by a phishing e-mail. Training – Photo by Gastro Editorial on Unsplash An employee unwittingly clicked on a malicious link, giving access to sensitive data and resulting in a loss of $2 mill</description>
    </item>
    <item>
      <title>ISO 27001 Clause 10.2 – Non-conformity management procedure</title>
      <link>https://certi360.com/en/iso-27001-clause-10-2-non-conformity-management-procedure/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-clause-10-2-non-conformity-management-procedure/</guid>
      <pubDate>Sat, 04 Jan 2025 00:00:00 GMT</pubDate>
      <description>Even the best-designed safety programs run into discrepancies. What to do in these situations? Photo by Etienne Girardet on Unsplash What does clause 10.2 actually require? Clause 10.2 of ISO 27001:2022 requires organizations to develop and maintain a process for dealing with non-conformances to the</description>
    </item>
    <item>
      <title>ISO 27001 Clause 10.1 – Continuous improvement</title>
      <link>https://certi360.com/en/iso-27001-clause-10-1-continuous-improvement/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-clause-10-1-continuous-improvement/</guid>
      <pubDate>Sun, 29 Dec 2024 00:00:00 GMT</pubDate>
      <description>As in other fields, in the world of information security, standing still is tantamount to going backwards! The aim of clause 10.1 of ISO 27001:2022 is to continue our race, our perpetual marathon, except that we’re not running to win a medal, but to preserve the security of our information. Clause 1</description>
    </item>
    <item>
      <title>My 10 Best reads of 2024</title>
      <link>https://certi360.com/en/my-10-best-reads-of-2024/</link>
      <guid isPermaLink="true">https://certi360.com/en/my-10-best-reads-of-2024/</guid>
      <pubDate>Sat, 21 Dec 2024 00:00:00 GMT</pubDate>
      <description>This year, I’ve been lucky enough to read quite a few books that have made an impression on me. I present to you my top 10 reads of 2024, with a few bonuses because, frankly, I couldn’t stop at 10! Books – Photo by Sebastien LE DEROUT on Unsplash 1. “New Cold Wars” by David […]</description>
    </item>
    <item>
      <title>ISO 27001 – Clause 9.3 – Management review</title>
      <link>https://certi360.com/en/iso-27001-clause-9-3-management-review/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-clause-9-3-management-review/</guid>
      <pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate>
      <description>Clause 9.3 of ISO 27001:2022 explains how to carry out a management review, which is an important step in ensuring that the Information Security Management System (ISMS) is working properly, and in the continuous improvement of the security program. Management meeting -Photo by Campaign Creators on</description>
    </item>
    <item>
      <title>How do I become an ISO27001 external auditor?</title>
      <link>https://certi360.com/en/how-do-i-become-an-iso27001-external-auditor/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-do-i-become-an-iso27001-external-auditor/</guid>
      <pubDate>Mon, 09 Dec 2024 00:00:00 GMT</pubDate>
      <description>ISO 27001 is an international standard that sets out the requirements for an information security management system (ISMS). So to become an ISO 27001 external auditor, there are several steps to follow in order to be recognized by a certification body. Photo by Agence Olloweb on Unsplash Training an</description>
    </item>
    <item>
      <title>ISO27001 – Clause 9.2 – Internal audit – Ensuring conformity</title>
      <link>https://certi360.com/en/iso27001-clause-9-2-internal-audit-ensuring-conformity/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-9-2-internal-audit-ensuring-conformity/</guid>
      <pubDate>Fri, 06 Dec 2024 00:00:00 GMT</pubDate>
      <description>Clause 9.2 of ISO 27001:2022 requires organizations to carry out regular internal audits of their information security management system (ISMS). Doing your taxes – Photo by Dimitri Karastelev on Unsplash These audits are essential to validate that the safety program is effective, identify weaknesses</description>
    </item>
    <item>
      <title>ISO27001 – Clause 9.1- Monitoring our dashboard</title>
      <link>https://certi360.com/en/iso27001-clause-9-1-monitoring-our-dashboard/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-9-1-monitoring-our-dashboard/</guid>
      <pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate>
      <description>Clause 9.1 of ISO27001:2022 requires organizations to carry out practical monitoring of their information security management system (ISMS). In concrete terms, we defined the security objectives of our security program when we implemented Clause 6.2. Now we need to monitor them. Obtain performance i</description>
    </item>
    <item>
      <title>Ladies, what to do before meeting a suitor?</title>
      <link>https://certi360.com/en/ladies-what-to-do-before-meeting-a-suitor/</link>
      <guid isPermaLink="true">https://certi360.com/en/ladies-what-to-do-before-meeting-a-suitor/</guid>
      <pubDate>Tue, 16 Jul 2024 00:00:00 GMT</pubDate>
      <description>It’s a Friday night, you’re chatting on a dating site and your suitor would like to meet you. What research should you do before meeting him? Dating – Photo by Priscilla Du Preez on Unsplash Meeting someone new is exciting, but it’s important to take a few precautions before embarking on a new encou</description>
    </item>
    <item>
      <title>Testing my business continuity strategies – what does it mean?</title>
      <link>https://certi360.com/en/testing-my-business-continuity-strategies-what-does-it-mean/</link>
      <guid isPermaLink="true">https://certi360.com/en/testing-my-business-continuity-strategies-what-does-it-mean/</guid>
      <pubDate>Fri, 03 May 2024 00:00:00 GMT</pubDate>
      <description>How do you know that the team has mastered the business continuity or incident management plan? Where the team knows how to react in the event of an incident. It’s easy! Let’s do a test. Practice – Photo by Niklas Tidbury on Unsplash Several types of test There are several types of test, each with [</description>
    </item>
    <item>
      <title>Dad, my friend had his cell phone stolen!</title>
      <link>https://certi360.com/en/dad-my-friend-had-his-cell-phone-stolen/</link>
      <guid isPermaLink="true">https://certi360.com/en/dad-my-friend-had-his-cell-phone-stolen/</guid>
      <pubDate>Tue, 26 Mar 2024 00:00:00 GMT</pubDate>
      <description>Oh no! What bad news, to realize that your phone has been stolen. It’s so frustrating and worrying, especially at your age, knowing that your phone is an extension of your social life. I know I’m being a wet blanket, but before I do anything after flight, you have to prepare before! Cellphone – Phot</description>
    </item>
    <item>
      <title>ISO27001 – Clause 8.3 – Dealing with risks</title>
      <link>https://certi360.com/en/iso27001-clause-8-3-dealing-with-risks/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-8-3-dealing-with-risks/</guid>
      <pubDate>Wed, 20 Mar 2024 00:00:00 GMT</pubDate>
      <description>Clause 8.3 of ISO 27001:2022 is crucial because it addresses how organizations should respond to the information security risks identified in the risk assessment (in clause 8.2). The clause stresses the importance of dealing with these risks effectively and consistently with the risk treatment metho</description>
    </item>
    <item>
      <title>As a CISO or CISO, why am I not on the management committee?</title>
      <link>https://certi360.com/en/as-a-ciso-or-ciso-why-am-i-not-on-the-management-committee/</link>
      <guid isPermaLink="true">https://certi360.com/en/as-a-ciso-or-ciso-why-am-i-not-on-the-management-committee/</guid>
      <pubDate>Tue, 12 Mar 2024 00:00:00 GMT</pubDate>
      <description>The role of a Chief Information Security Officer (CISO) or the Information Systems Security Manager (ISSM) is a very important role for any organization, especially in today’s context of growing threats to information security. Army commander – Photo by British Library on Unsplash That said, I recei</description>
    </item>
    <item>
      <title>ISO27001 – Clause 8.2- Risk assessment</title>
      <link>https://certi360.com/en/iso27001-clause-8-2-risk-assessment/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-8-2-risk-assessment/</guid>
      <pubDate>Fri, 01 Mar 2024 00:00:00 GMT</pubDate>
      <description>Clause 8.2 is one of the most important clauses in the standard, as it forms the basis for all other information security controls. Risk management is the cornerstone of information security in any organization. ISO 27001:2022 places particular emphasis on the importance of this notion through claus</description>
    </item>
    <item>
      <title>ISO27001 – Clause 8.1- Operations planning</title>
      <link>https://certi360.com/en/iso27001-clause-8-1-operations-planning/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-8-1-operations-planning/</guid>
      <pubDate>Mon, 26 Feb 2024 00:00:00 GMT</pubDate>
      <description>Clause 8.1 of ISO 27001 underlines the importance of rigorous planning and control of information security operations within an organization. In concrete terms, in clause 6 we defined our objectives, now we have to bring them to life. Planning – Photo by Patrick Perkins on Unsplash Like the foundati</description>
    </item>
    <item>
      <title>How do you prepare a digital will?</title>
      <link>https://certi360.com/en/how-do-you-prepare-a-digital-will/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-do-you-prepare-a-digital-will/</guid>
      <pubDate>Thu, 15 Feb 2024 00:00:00 GMT</pubDate>
      <description>We all know that when we draw up our wills, we need to list our bank accounts, other financial institutions and assets that will be sold after our death, as well as the strategies for distributing or sharing them with our loved ones. But these days, in this “dematerialized” world, our lives are incr</description>
    </item>
    <item>
      <title>Managing information security in the supply chain</title>
      <link>https://certi360.com/en/managing-information-security-in-the-supply-chain/</link>
      <guid isPermaLink="true">https://certi360.com/en/managing-information-security-in-the-supply-chain/</guid>
      <pubDate>Fri, 09 Feb 2024 00:00:00 GMT</pubDate>
      <description>I come across a survey report on the subject of supply chain risk management from Gartner 2023. It states that “supply chain attacks are on the rise, with 63% of respondents saying their organization has suffered a supply chain attack in the past year”. A number of questions have popped into my head</description>
    </item>
    <item>
      <title>In search of artifacts: What does a compliance auditor hope to discover?</title>
      <link>https://certi360.com/en/in-search-of-artifacts-what-does-a-compliance-auditor-hope-to-discover/</link>
      <guid isPermaLink="true">https://certi360.com/en/in-search-of-artifacts-what-does-a-compliance-auditor-hope-to-discover/</guid>
      <pubDate>Fri, 02 Feb 2024 00:00:00 GMT</pubDate>
      <description>An artifact is an element created as an output from a process or project. An artifact can be a document, record, report or tool used to plan, organize, implement, monitor and control ISMS-related activities. It is proof that the activity actually took place. Artifacts – Photo by Trnava University on</description>
    </item>
    <item>
      <title>Protection of personal information in the context of Bill 25 – The difference between data…</title>
      <link>https://certi360.com/en/protection-of-personal-information-in-the-context-of-bill-25-the-difference-between-data/</link>
      <guid isPermaLink="true">https://certi360.com/en/protection-of-personal-information-in-the-context-of-bill-25-the-difference-between-data/</guid>
      <pubDate>Mon, 29 Jan 2024 00:00:00 GMT</pubDate>
      <description>Today we’re going to explore the difference between de-identified data and anonymized anonymized data. These two terms come up a lot in the field of privacy protection, and understanding the difference between them is essential for any organization handling personal information. It’s not only a ques</description>
    </item>
    <item>
      <title>ISO27001 – Clause 7.5 – Document management</title>
      <link>https://certi360.com/en/iso27001-clause-7-5-document-management/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-7-5-document-management/</guid>
      <pubDate>Mon, 22 Jan 2024 00:00:00 GMT</pubDate>
      <description>When it comes to information security, every detail counts, including the way information is created, stored, maintained and destroyed. Clause 7.5 of ISO 27001 addresses the “management of documented information”, an aspect often overlooked, but nonetheless crucial to the implementation of an effect</description>
    </item>
    <item>
      <title>[Article 5] Stalking – Endure porn disclosure and hypertrucage!</title>
      <link>https://certi360.com/en/article-5-stalking-endure-porn-disclosure-and-hypertrucage/</link>
      <guid isPermaLink="true">https://certi360.com/en/article-5-stalking-endure-porn-disclosure-and-hypertrucage/</guid>
      <pubDate>Sat, 30 Dec 2023 00:00:00 GMT</pubDate>
      <description>This is the last article in my series on stalking. This behavior is very disturbing and destabilizing, especially with the use of artificial intelligence tools that can create false images of you, but naked, or superimposed in an adult video allowing people to be taken advantage of. “Revenge porn” o</description>
    </item>
    <item>
      <title>Best reads of 2023</title>
      <link>https://certi360.com/en/best-reads-of-2023/</link>
      <guid isPermaLink="true">https://certi360.com/en/best-reads-of-2023/</guid>
      <pubDate>Sun, 24 Dec 2023 00:00:00 GMT</pubDate>
      <description>Here we are at that time of year when we pause and look back at all the work we’ve done, and in my case, I’m also looking back at all the books I’ve read this year. I realize that few books have really hooked me this year, looking at the list I rather took time […]</description>
    </item>
    <item>
      <title>[Article 4] Stalking – How can I tell if someone is spying on me?</title>
      <link>https://certi360.com/en/article-4-stalking-how-can-i-tell-if-someone-is-spying-on-me/</link>
      <guid isPermaLink="true">https://certi360.com/en/article-4-stalking-how-can-i-tell-if-someone-is-spying-on-me/</guid>
      <pubDate>Mon, 18 Dec 2023 00:00:00 GMT</pubDate>
      <description>The issue of security and digital privacy is paramount. As technology advances, it’s essential that we continue to be concerned about protecting our personal information. If you’re wondering how to detect if you’re being spied on with technological tools, here are some basic tips. [Links to article</description>
    </item>
    <item>
      <title>[Article 3] Stalking – Prevent it!</title>
      <link>https://certi360.com/en/article-3-stalking-prevent-it/</link>
      <guid isPermaLink="true">https://certi360.com/en/article-3-stalking-prevent-it/</guid>
      <pubDate>Thu, 14 Dec 2023 00:00:00 GMT</pubDate>
      <description>Today, I present the third article in a series on harassment. In this article, I seek to understand how to prevent harassment. [Links to article 1] I hope this article will help raise awareness of the issue and encourage collective thinking to reduce harassment. It’s crucial that we work together to</description>
    </item>
    <item>
      <title>[Article 2]Stalking – Its different forms.</title>
      <link>https://certi360.com/en/article-2stalking-its-different-forms/</link>
      <guid isPermaLink="true">https://certi360.com/en/article-2stalking-its-different-forms/</guid>
      <pubDate>Tue, 12 Dec 2023 00:00:00 GMT</pubDate>
      <description>Following on from the previous article, in which I explored the laws surrounding stalking, allow me to present a few concrete examples that illustrate in greater detail what stalking is all about. You can rediscover the article by following thelink here to article no. 1! Harassment is a worrying soc</description>
    </item>
    <item>
      <title>[Article 1] Criminal harassment – The laws</title>
      <link>https://certi360.com/en/article-1-criminal-harassment-the-laws/</link>
      <guid isPermaLink="true">https://certi360.com/en/article-1-criminal-harassment-the-laws/</guid>
      <pubDate>Sun, 03 Dec 2023 00:00:00 GMT</pubDate>
      <description>On the night of Friday August 25 to Saturday August 26, 2023, Ianick Lamontagne committed an irreparable act: the murder of his children, followed by his own suicide. I was so surprised and shocked by this tragic story that I wrote about it in various media. I later discovered that he had clearly cr</description>
    </item>
    <item>
      <title>ISO27001 – Clause 7.3 – Raising awareness</title>
      <link>https://certi360.com/en/iso27001-clause-7-3-raising-awareness/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-7-3-raising-awareness/</guid>
      <pubDate>Fri, 25 Aug 2023 00:00:00 GMT</pubDate>
      <description>Information security is a crucial issue in today’s digital age. Yet we often only realize its importance after we’ve been the victim of a cyber-attack or security incident. Clause 7.3 of ISO27001 requires that not only employees, but all stakeholders in an organization, are made aware of the importa</description>
    </item>
    <item>
      <title>ISO27001 – Clause 7.2 – Skills</title>
      <link>https://certi360.com/en/iso27001-clause-7-2-skills/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-7-2-skills/</guid>
      <pubDate>Mon, 14 Aug 2023 00:00:00 GMT</pubDate>
      <description>Clause 7.2 is designed to ensure that those who have an impact on the organization’s information security have the appropriate and necessary skills to carry out their responsibilities properly. Competence – Photo by Ahmed M Elpahwee on Unsplash Specifically, clause 7.2 requires the organization : De</description>
    </item>
    <item>
      <title>ISO27001 – Clause 7.1 – Resources</title>
      <link>https://certi360.com/en/iso27001-clause-7-1-resources/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-7-1-resources/</guid>
      <pubDate>Tue, 25 Jul 2023 00:00:00 GMT</pubDate>
      <description>The organization must identify and provide the resources needed to establish, implement, maintain and continuously improve the information security management system (ISMS). Resources – Photo by Sincerely Media on Unsplash Management has already defined its safety objectives (Clause 6.2), and must t</description>
    </item>
    <item>
      <title>ISO 27001 – Clause 6.3 – Change planning</title>
      <link>https://certi360.com/en/iso-27001-clause-6-3-change-planning/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-clause-6-3-change-planning/</guid>
      <pubDate>Fri, 21 Jul 2023 00:00:00 GMT</pubDate>
      <description>Planning changes to an information security management system (ISMS) is important for several reasons. Firstly, it helps to minimize the impact on operations. Then there’s the fact that unplanned changes can lead to breakdowns or malfunctions in the organization. Have you ever installed an update on</description>
    </item>
    <item>
      <title>ISO 27001 – Clause 6.2 – Objective – How to measure the objectives of a security program</title>
      <link>https://certi360.com/en/iso-27001-clause-6-2-objective-how-to-measure-the-objectives-of-a-security-program/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27001-clause-6-2-objective-how-to-measure-the-objectives-of-a-security-program/</guid>
      <pubDate>Mon, 17 Jul 2023 00:00:00 GMT</pubDate>
      <description>Setting a goal is the best way to achieve it, otherwise how do we know when we’ve succeeded? By defining your information security objectives, you can clearly determine what you want to achieve. to achieve to protect the company’s systems and data against internal and external threats. What do we wa</description>
    </item>
    <item>
      <title>Your transition plan to ISO27001 version 2022!</title>
      <link>https://certi360.com/en/your-transition-plan-to-iso27001-version-2022/</link>
      <guid isPermaLink="true">https://certi360.com/en/your-transition-plan-to-iso27001-version-2022/</guid>
      <pubDate>Sat, 08 Jul 2023 00:00:00 GMT</pubDate>
      <description>It’s now almost a year since ISO 27001:2013 was replaced by the new version named ISO 27001:2022. Here’s your transition plan! Change – Photo by Suzanne D. Williams on Unsplash This 2022 version of the standard enhances requirements and introduces new elements to meet changing challenges and new thr</description>
    </item>
    <item>
      <title>ISO27001 – Clause 6.1 – Actions to address risks and opportunities!</title>
      <link>https://certi360.com/en/iso27001-clause-6-1-actions-to-address-risks-and-opportunities/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-6-1-actions-to-address-risks-and-opportunities/</guid>
      <pubDate>Mon, 19 Jun 2023 00:00:00 GMT</pubDate>
      <description>Information security risk management is the set of actions taken by an organization to understand and reduce the effects of risk. Clause 6.1 of ISO 27001 addresses actions to identify threats, estimate their risk levels and manage the action plan to prevent or repair the impact of these risks. Photo</description>
    </item>
    <item>
      <title>ISO27001 Clause 5.3 – Information security roles</title>
      <link>https://certi360.com/en/iso27001-clause-5-3-information-security-roles/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-5-3-information-security-roles/</guid>
      <pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate>
      <description>Roles, responsibilities and power sharing within an organization are of the utmost importance when it comes to information security. Understanding who is responsible for what, and the authority associated with each role, is essential for organizations to ensure the security of their data and network</description>
    </item>
    <item>
      <title>ISO27001 Clause 5.2 – Policy</title>
      <link>https://certi360.com/en/iso27001-clause-5-2-policy/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-5-2-policy/</guid>
      <pubDate>Fri, 17 Feb 2023 00:00:00 GMT</pubDate>
      <description>Policy is the equivalent of a corporate mission, since without a mission there is no corporate project. So, without a policy, information security management has no objective and, unfortunately, little chance of success. Politics – Photo by Marco Oriolesi on Unsplash An information security policy i</description>
    </item>
    <item>
      <title>ISO27001 Clause 5.1 – Commitment and leadership</title>
      <link>https://certi360.com/en/iso27001-clause-5-1-commitment-and-leadership/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-5-1-commitment-and-leadership/</guid>
      <pubDate>Sun, 12 Feb 2023 00:00:00 GMT</pubDate>
      <description>Photo by Brooke Lark on Unsplash The organization’s management is key to ensuring that ISO 27001 requirements are met and that the ISMS is effective. It’s important to understand that ISO27001 is a standard that needs to be implemented from the top down. So, the organization’s management must show l</description>
    </item>
    <item>
      <title>ISO27001 Clause 4.4 – ISMS maintenance</title>
      <link>https://certi360.com/en/iso27001-clause-4-4-isms-maintenance/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-4-4-isms-maintenance/</guid>
      <pubDate>Mon, 06 Feb 2023 00:00:00 GMT</pubDate>
      <description>Clause 4.4 of the ISO27001 standard is one of the smallest in size, but the one that, in my opinion, has the greatest day-to-day impact on the organization. Maintenance – Photo by Markus Spiske on Unsplash Establishing and implementing In the context of ISO 27001 on information security, the term “e</description>
    </item>
    <item>
      <title>ISO27001 – Clause 4.3 – determining the scope of the security program.</title>
      <link>https://certi360.com/en/iso27001-clause-4-3-determining-the-scope-of-the-security-program/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-4-3-determining-the-scope-of-the-security-program/</guid>
      <pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate>
      <description>The scope of an ISMS (Information Security Management System) is crucial, as it defines the direction and objective that the security team must follow. Direction – Photo by Nick Fewings on Unsplash The scope of the Information Security Management System (ISMS) is the set of activities, processes and</description>
    </item>
    <item>
      <title>ISO27001 – Clause 4.2 – Understanding stakeholder needs and expectations</title>
      <link>https://certi360.com/en/iso27001-clause-4-2-understanding-stakeholder-needs-and-expectations/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-4-2-understanding-stakeholder-needs-and-expectations/</guid>
      <pubDate>Thu, 26 Jan 2023 00:00:00 GMT</pubDate>
      <description>As we often say, information security is everybody’s business. We need to identify and understand the needs of this world. Photo by Matheus Ferrero on Unsplash Clause 4.2 of the ISO 27001 standard on information security calls for stakeholders to be identified, as they have a significant impact and</description>
    </item>
    <item>
      <title>ISO27001 Clause 4.1 – Understanding the organization and its context</title>
      <link>https://certi360.com/en/iso27001-clause-4-1-understanding-the-organization-and-its-context/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso27001-clause-4-1-understanding-the-organization-and-its-context/</guid>
      <pubDate>Wed, 25 Jan 2023 00:00:00 GMT</pubDate>
      <description>To begin with, are we able to define who the organization is in clear terms? Photo by Jametlene Reskp on Unsplash This stage consists of determining an organization’s internal and external challenges. It is an important process for understanding the risks to which the company is exposed. It also hel</description>
    </item>
    <item>
      <title>What’s the difference between an information security incident and a non-compliance?</title>
      <link>https://certi360.com/en/whats-the-difference-between-an-information-security-incident-and-a-non-compliance/</link>
      <guid isPermaLink="true">https://certi360.com/en/whats-the-difference-between-an-information-security-incident-and-a-non-compliance/</guid>
      <pubDate>Mon, 23 Jan 2023 00:00:00 GMT</pubDate>
      <description>Photo by Possessed Photography on Unsplash When implementing a management system (such as SGSI-ISO27001) we need to understand the difference between several concepts, the one I’d like to discuss with you is between an event, an incident and a non-conformity. Can you tell the difference between thes</description>
    </item>
    <item>
      <title>5 Steps to becoming an ISO27001? external auditor</title>
      <link>https://certi360.com/en/5-steps-to-becoming-an-iso27001-external-auditor/</link>
      <guid isPermaLink="true">https://certi360.com/en/5-steps-to-becoming-an-iso27001-external-auditor/</guid>
      <pubDate>Thu, 19 Jan 2023 00:00:00 GMT</pubDate>
      <description>Photo by Glenn Carstens-Peters on Unsplash Becoming an ISO 27001 external auditor requires a combination of training, professional experience and certification. ISO 27001 is an international framework for information security management, providing guidelines for protecting sensitive corporate inform</description>
    </item>
    <item>
      <title>Best reads of 2022.</title>
      <link>https://certi360.com/en/best-reads-of-2022/</link>
      <guid isPermaLink="true">https://certi360.com/en/best-reads-of-2022/</guid>
      <pubDate>Wed, 28 Dec 2022 00:00:00 GMT</pubDate>
      <description>Photo by Ashim D’Silva on Unsplash You may have been discovering this slowly over the last few years as you’ve read me talking about books, but I really do enjoy reading! In short, during this year, 2022, I’ve done a lot of reading, some of which doesn’t deserve your attention, but others that do! S</description>
    </item>
    <item>
      <title>How much does it cost to obtain ISO27001 certification?</title>
      <link>https://certi360.com/en/how-much-does-it-cost-to-obtain-iso27001-certification/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-much-does-it-cost-to-obtain-iso27001-certification/</guid>
      <pubDate>Mon, 24 Oct 2022 00:00:00 GMT</pubDate>
      <description>The question of the cost of an ISO27001 certification project frequently comes up, and rightly so, since this certification is based on the most widely recognized international standard for information security management. Photo by Ibrahim Rifath on Unsplash Companies are increasingly being asked by</description>
    </item>
    <item>
      <title>ISO 27017 – Guide for the use of cloud services.</title>
      <link>https://certi360.com/en/iso-27017-guide-for-the-use-of-cloud-services/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27017-guide-for-the-use-of-cloud-services/</guid>
      <pubDate>Sat, 25 Jun 2022 00:00:00 GMT</pubDate>
      <description>Cloud computing is becoming increasingly popular as companies look for ways to improve efficiency and reduce costs. Security in this context is essential. Now comes the international standard ISO 27017, providing guidance on how to implement security controls for cloud services for both customers an</description>
    </item>
    <item>
      <title>How can you trust an auditor’s report?</title>
      <link>https://certi360.com/en/how-can-you-trust-an-auditors-report/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-can-you-trust-an-auditors-report/</guid>
      <pubDate>Sun, 15 May 2022 00:00:00 GMT</pubDate>
      <description>In a world of compliance with laws, regulations and standards, it can be difficult to know whether or not to trust an auditor’s report. Trust is an important value in all business contexts. The Russian proverb “Trust, but verify” takes on its full meaning. Your trust rests on the work of auditors wh</description>
    </item>
    <item>
      <title>PCI-DSS 4.0 – What’s new?</title>
      <link>https://certi360.com/en/pci-dss-4-0-whats-new/</link>
      <guid isPermaLink="true">https://certi360.com/en/pci-dss-4-0-whats-new/</guid>
      <pubDate>Wed, 13 Apr 2022 00:00:00 GMT</pubDate>
      <description>When I received notification of the standard’s publication on March 31, 2022, I thought it was an April fool’s joke. So I let the day pass to check the next day, and well no – it’s just an April fool’s joke.The standard has indeed been published! Transition period The transition period is from March</description>
    </item>
    <item>
      <title>ISO 27018 – privacy protection for cloud processors?</title>
      <link>https://certi360.com/en/iso-27018-privacy-protection-for-cloud-processors/</link>
      <guid isPermaLink="true">https://certi360.com/en/iso-27018-privacy-protection-for-cloud-processors/</guid>
      <pubDate>Fri, 25 Mar 2022 00:00:00 GMT</pubDate>
      <description>Are you a cloud service provider? Do your customers process personal information? Do your customers use your platform to deliver their services? Do you offer data processing options that your customers can tailor to their needs? If these 4 conditions apply to your organization, then this standard is</description>
    </item>
    <item>
      <title>Password manager – how and why do I need one?</title>
      <link>https://certi360.com/en/password-manager-how-and-why-do-i-need-one/</link>
      <guid isPermaLink="true">https://certi360.com/en/password-manager-how-and-why-do-i-need-one/</guid>
      <pubDate>Thu, 10 Mar 2022 00:00:00 GMT</pubDate>
      <description>A few days ago I asked a question on the LinkedIn platform, namely what would be the best choice for a password vault application. Survey results on LinkedIn Emergency – have a password vault! Each of us has dozens of passwords for the different sites we visit, be it Facebook, Twitter, Medium, Googl</description>
    </item>
    <item>
      <title>Personal information: Do you know your role?</title>
      <link>https://certi360.com/en/personal-information-do-you-know-your-role/</link>
      <guid isPermaLink="true">https://certi360.com/en/personal-information-do-you-know-your-role/</guid>
      <pubDate>Mon, 07 Mar 2022 00:00:00 GMT</pubDate>
      <description>There are two distinct roles when it comes to corporate responsibility for managing personal information. Controllers and processors of personal information. What is the difference between these two roles in the context of processing (collecting, displaying, storing, analyzing, transmitting, treatin</description>
    </item>
    <item>
      <title>How do I draw up a communication plan?</title>
      <link>https://certi360.com/en/how-do-i-draw-up-a-communication-plan/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-do-i-draw-up-a-communication-plan/</guid>
      <pubDate>Tue, 01 Mar 2022 00:00:00 GMT</pubDate>
      <description>A communication plan is a formal document that describes how information will be shared between the organization and its stakeholders, both internal and external. The stated aim of such a plan is to anticipate the actions to be taken in given circumstances. For example, in the event of a security in</description>
    </item>
    <item>
      <title>Why do companies fail their security audits?</title>
      <link>https://certi360.com/en/why-do-companies-fail-their-security-audits/</link>
      <guid isPermaLink="true">https://certi360.com/en/why-do-companies-fail-their-security-audits/</guid>
      <pubDate>Tue, 22 Feb 2022 00:00:00 GMT</pubDate>
      <description>Lately, I’ve been doing a lot of compliance audits (internal and external), mainly for PCIDSS and ISO standards. (22301, 27001, 27017, 27018, 27035, 27701) I love this job, but I’ve noticed that many companies fail to manage their security programs for various reasons. flickr.com The main reason I s</description>
    </item>
    <item>
      <title>New edition of ISO27002, version 2022</title>
      <link>https://certi360.com/en/new-edition-of-iso27002-version-2022/</link>
      <guid isPermaLink="true">https://certi360.com/en/new-edition-of-iso27002-version-2022/</guid>
      <pubDate>Thu, 17 Feb 2022 00:00:00 GMT</pubDate>
      <description>On February 15, 2022, a revision of the ISO/IEC 27002 standard is published and available to all. You can get it here: https://www.iso.org/standard/75652.html This is really good news, as the standard really needed a refresh and modernization. Here’s a reminder of the changes Number of safety measur</description>
    </item>
    <item>
      <title>How to combat listener fatigue?</title>
      <link>https://certi360.com/en/how-to-combat-listener-fatigue/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-to-combat-listener-fatigue/</guid>
      <pubDate>Fri, 11 Feb 2022 00:00:00 GMT</pubDate>
      <description>During this festive period of exchange and discussion about our mental health, I’d like to bring you a subject that isn’t often discussed in the auditing community, but which I believe is a major issue both in terms of the quality of the work carried out and the results obtained. Beware of listener</description>
    </item>
    <item>
      <title>How do you structure your corporate cybersecurity program?</title>
      <link>https://certi360.com/en/how-do-you-structure-your-corporate-cybersecurity-program/</link>
      <guid isPermaLink="true">https://certi360.com/en/how-do-you-structure-your-corporate-cybersecurity-program/</guid>
      <pubDate>Tue, 08 Feb 2022 00:00:00 GMT</pubDate>
      <description>What you need to know to manage a minimal information security program in a corporate context. Source: https://www.cam.ac.uk/news/cambridge-to-host-transatlantic-cyber-security-competition Before getting started, it’s important to note that there is no single structure or model for information secur</description>
    </item>
    <item>
      <title>PCI DSS – Credit card management!</title>
      <link>https://certi360.com/en/pci-dss-credit-card-management/</link>
      <guid isPermaLink="true">https://certi360.com/en/pci-dss-credit-card-management/</guid>
      <pubDate>Wed, 02 Feb 2022 00:00:00 GMT</pubDate>
      <description>Do your customers pay you with their credit cards? Then the PCI DSS standard is for you! The origin of the standard : Before PCI DSS, credit card companies (Visa, MasterCard, etc.) had their own independent security programs. These security programs, which differed from one organization to another,</description>
    </item>
    <item>
      <title>Quebec Bill 64 – Year 1 of 3 – Here are the articles that come into force.</title>
      <link>https://certi360.com/en/quebec-bill-64-year-1-of-3-here-are-the-articles-that-come-into-force/</link>
      <guid isPermaLink="true">https://certi360.com/en/quebec-bill-64-year-1-of-3-here-are-the-articles-that-come-into-force/</guid>
      <pubDate>Mon, 17 Jan 2022 00:00:00 GMT</pubDate>
      <description>We’re in the first year of a three-year implementation period. Here’s what you need to know about this first year! Given the fluid nature of information, the ease with which it can be shared from one provider to another, and the reputational losses and issues involved. The government (and your autho</description>
    </item>
    <item>
      <title>What is a SOC2 report?</title>
      <link>https://certi360.com/en/what-is-a-soc2-report/</link>
      <guid isPermaLink="true">https://certi360.com/en/what-is-a-soc2-report/</guid>
      <pubDate>Mon, 10 Jan 2022 00:00:00 GMT</pubDate>
      <description>Your company provides services to its customers? and your customers ask you for a SOC 2 type 2 report? Your customers want this report to validate your security compliance, to reassure their customers, or perhaps because they themselves have to comply with information security standards. A SOC (Serv</description>
    </item>
    <item>
      <title>What is ISO/IEC 27001?</title>
      <link>https://certi360.com/en/what-is-iso-iec-27001/</link>
      <guid isPermaLink="true">https://certi360.com/en/what-is-iso-iec-27001/</guid>
      <pubDate>Fri, 07 Jan 2022 00:00:00 GMT</pubDate>
      <description>ISO/IEC 27001 formally defines an information security management system (ISMS) as a set of activities designed to manage information security risks. An ISMS is a management framework through which the organization identifies, analyzes and addresses information security risks. The ISMS ensures that</description>
    </item>
    <item>
      <title>Writing a cybersecurity incident report?</title>
      <link>https://certi360.com/en/writing-a-cybersecurity-incident-report/</link>
      <guid isPermaLink="true">https://certi360.com/en/writing-a-cybersecurity-incident-report/</guid>
      <pubDate>Mon, 03 Jan 2022 00:00:00 GMT</pubDate>
      <description>When a cybersecurity incident occurs, it’s important to record all the details so you can remember it and prevent it from happening again. This includes information such as who was involved, who was affected by the event, when the incident occurred and why. The more detail you provide in your report</description>
    </item>
    <item>
      <title>28 questions to assess your teleworking policy</title>
      <link>https://certi360.com/en/28-questions-to-assess-your-teleworking-policy/</link>
      <guid isPermaLink="true">https://certi360.com/en/28-questions-to-assess-your-teleworking-policy/</guid>
      <pubDate>Tue, 28 Dec 2021 00:00:00 GMT</pubDate>
      <description>Here we are again, in a period of confinement due to Covid-19. I thought it was time to evaluate its telecommuting policies. It’s important to remember that telecommuting refers to any work performed outside the traditional office setting. This includes, of course, working from home, but also at fri</description>
    </item>
    <item>
      <title>My best reads of 2021!</title>
      <link>https://certi360.com/en/my-best-reads-of-2021/</link>
      <guid isPermaLink="true">https://certi360.com/en/my-best-reads-of-2021/</guid>
      <pubDate>Fri, 24 Dec 2021 00:00:00 GMT</pubDate>
      <description>Source: Flikr.com Here we are again at the end of the year, and the confinement and sanitary measures have only increased my love of reading, which I must admit was already very strong! Anyway, here’s my list of the reads I’ve enjoyed most in this year 2021. Liberté 45 – By Pierre-Yves McSween Of co</description>
    </item>
    <item>
      <title>6 steps to managing information security incidents</title>
      <link>https://certi360.com/en/6-steps-to-managing-information-security-incidents/</link>
      <guid isPermaLink="true">https://certi360.com/en/6-steps-to-managing-information-security-incidents/</guid>
      <pubDate>Tue, 21 Dec 2021 00:00:00 GMT</pubDate>
      <description>In the course of my work, I come across all kinds of companies, but too many have no procedures or methods for managing incidents. So I’m writing this article for them. So that they can get a complete picture of the process and take control of it. Photo by Elisa Ventur on Unsplash First things […]</description>
    </item>
  </channel>
</rss>