URM Consulting
URM Consulting
  • Видео 72
  • Просмотров 166 043
InfoSec Insider Podcast - Preparing For a PCI DSS v4 Assessment
In this episode of InfoSec Insider, Alastair Stewart, Senior Consultant and Qualified Security Assessor (QSA) at URM, breaks down the changes to assessments in v4.0 of the Payment Card Industry Data Security Standard (PCI DSS), and how organisations can prepare for their v4 assessments. Alastair leverages more than a decade of experience with the PCI DSS to discuss:
• The types of evidence the PCI DSS requires, whether there are any new evidence types in v4 and preparing evidence in advance of your assessment
• How QSAs collected evidence when assessing previous versions of the PCI DSS and how this has changed in v4
• How these changes will impact assessments against v4
• His key advice for ...
Просмотров: 1

Видео

InfoSec Insider Podcast - Mitigating Cyber Risks
Просмотров 4621 день назад
In this episode of InfoSec Insider - Talk Cyber, George Ryan, Consultant at URM, breaks down the current state of cyber security in the modern business landscape and the common cyber security failings and challenges he sees organisations face, as well as offering key advice and guidance on what organisations can do to protect against these threats. George leverages his extensive experience assi...
InfoSec Insider Podcast - Mistakes to Avoid When Implementing & Maintaining an ISO 27001 ISMS
Просмотров 1328 дней назад
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, breaks down the common mistakes and challenges organisations come up against on both sides of their certification assessment, i.e., before the external assessment when the Information Security Management System (ISMS) is first being implemented, and after certification has been achieved and the ISMS is being maintain...
InfoSec Insider Podcast - Who Needs ROPA and Why?
Просмотров 8Месяц назад
In this episode of InfoSec Insider - Talk DP, Stuart Skelly, a Senior GRC Consultant at URM, explains records of processing activities (ROPAs), a key document that almost every organisation must create and maintain in order to comply with the General Data Protection Regulation (GDPR). Stuart leverages his 25 years of specialisation in data protection law to discuss: • What a ROPA is, which orga...
Webinar - Penetration Testing for Cloud-Native Organisations - INTRO
Просмотров 19Месяц назад
With the rate of cloud adoption accelerating, traditional penetration testing often falls short in addressing the unique challenges that cloud environments present. Cloud-native architectures, with their dependence on APIs, containerisation, and dynamic scaling, introduce new attack surfaces that require specialised testing approaches. In this latest webinar from URM, we will examine why conven...
InfoSec Insider Podcast - ISO 42001 and AI Perspectives
Просмотров 22Месяц назад
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, breaks down the purpose and structure of the recently released ISO 42001, the International Standard for Artificial Intelligence Management Systems (AIMS), as well as explaining the Standard’s use of AI ‘perspectives’. Neil leverages his 20 years’ working with a range of risk and information security-related standards to ...
Webinar - DSAR - a Nightmare for Privacy Professionals - INTRO
Просмотров 40Месяц назад
Under the General Data Protection Regulation (GDPR), individuals are provided with the ‘right to access’ their personal data. To exercise this right, individuals can make a data subject access request (DSAR) of any organisation that holds their personal data, which must be responded to and fulfilled by the organisation within a defined timeframe. Responding to DSARs can be time-consuming and re...
InfoSec Insider Podcast - Data Protection Considerations for Monitoring Employees
Просмотров 25Месяц назад
In this episode of InfoSec Insider - Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explores the challenges of maintaining data protection compliance whilst conducting workplace monitoring, particularly in light of the workforce’s ever-increasing mobility, and how these challenges can be overcome. Martin leverages his 20 years of experience in information management and data...
InfoSec Insider Podcast - What is the CIA Security Triad?
Просмотров 24Месяц назад
In this episode of InfoSec Insider, Les Krause-Whiteing, Senior Consultant at URM, breaks down the concepts of confidentiality, integrity and availability (CIA), the 3 fundamental principles on which strong information security is built, and why they are so important to the effective and comprehensive information security management. Les draws upon his extensive experience helping organisations...
InfoSec Insider Podcast - Data Protection Considerations for Artificial Intelligence (AI)
Просмотров 302 месяца назад
In this episode of InfoSec Insider - Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explores some of the considerations and challenges of maintaining compliance with data protection legislation, such as the General Data Protection Regulation (GDPR), when developing and deploying artificial intelligence (AI) technology. Martin leverages his 20 years of experience in informati...
InfoSec Insider Podcast - ISO, IAF and Climate Change Considerations
Просмотров 52 месяца назад
In this episode of InfoSec Insider, Stuart Moran, Senior Consultant at URM, explores the addition of climate change considerations to 31 management system standards by the International Standards Organization (ISO) and the International Accreditation Forum (IAF). Stuart draws upon more than 20 years of experience working with a wide range of ISO management system standards to discuss: - What th...
InfoSec Insider Podcast - Tips for GDPR Compliance
Просмотров 352 месяца назад
In this episode of InfoSec Insider - Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides some hints and tips on how to achieve and maintain compliance with the General Data Protection Regulation (GDPR), with a particular focus on the key documentation organisations need to have in place to comply. Stuart leverages over 25 years of experience to discuss: - The importance o...
Webinar - Cyber Essentials and Cyber Essentials Plus Successful Certification - INTRO
Просмотров 782 месяца назад
Cyber Essentials is a UK government-backed cyber security certification scheme, which defines fundamental technical controls organisations should have in place to ensure they are protected against the most common internet-based cyber attacks. The National Cyber Security Centre (NCSC) introduced Cyber Essentials in 2014 and has made several updates since to keep pace with evolving cyber threats ...
InfoSec Insider Podcast - Common Pitfalls with ISO 27001
Просмотров 202 месяца назад
In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, highlights the common pitfalls and mistakes he frequently sees organisations make when implementing ISO 27001, and explores the steps you can take to avoid these pitfalls. Frazer draws upon his 15 years of experience assisting organisations to implement ISO 27001 to discuss: The most common mistakes made and challen...
Webinar - ISO 13485: What, Why and How INTRO
Просмотров 212 месяца назад
ISO 13485 is an international quality management system (QMS) standard which has been developed specifically for the medical device industry and is one of the fastest growing ISO standards. It outlines the requirements for establishing a QMS that demonstrates an organisation’s capability (through the entire lifecycle, from design to disposal) to consistently and safely deliver medical devices a...
InfoSec Insider Podcast - Facial Recognition Technology
Просмотров 193 месяца назад
InfoSec Insider Podcast - Facial Recognition Technology
InfoSec Insider Podcast - ISO 9001 Implementation
Просмотров 233 месяца назад
InfoSec Insider Podcast - ISO 9001 Implementation
Webinar - SOC 2: What, Why and How - INTRO
Просмотров 373 месяца назад
Webinar - SOC 2: What, Why and How - INTRO
InfoSec Insider Podcast - Fines Imposed by the ICO in 2023
Просмотров 223 месяца назад
InfoSec Insider Podcast - Fines Imposed by the ICO in 2023
InfoSec Insider Podcast - PCI DSS - New Requirements for E-Commerce
Просмотров 383 месяца назад
InfoSec Insider Podcast - PCI DSS - New Requirements for E-Commerce
InfoSec Insider Podcast - Everything You Need to Know About DSARs
Просмотров 343 месяца назад
InfoSec Insider Podcast - Everything You Need to Know About DSARs
InfoSec Insider Podcast - Certificate in Information Security Management Principles (CISMP)
Просмотров 1264 месяца назад
InfoSec Insider Podcast - Certificate in Information Security Management Principles (CISMP)
InfoSec Insider Podcast - GDPR Back to Basics
Просмотров 504 месяца назад
InfoSec Insider Podcast - GDPR Back to Basics
InfoSec Insider Podcast - Comparison of ISO 9001 and ISO 27001
Просмотров 245 месяцев назад
InfoSec Insider Podcast - Comparison of ISO 9001 and ISO 27001
Webinar - 5 Steps to Improve Your Supplier Information Security Risk Management - INTRO
Просмотров 665 месяцев назад
Webinar - 5 Steps to Improve Your Supplier Information Security Risk Management - INTRO
3 Peaks Challenge Interview. Martin's motivation.
Просмотров 466 месяцев назад
3 Peaks Challenge Interview. Martin's motivation.
Webinar - Getting the Most From Your Pen Testing Programme - INTRO
Просмотров 296 месяцев назад
Webinar - Getting the Most From Your Pen Testing Programme - INTRO
Webinar - Data Protection in the UK: What Next? - INTRO
Просмотров 827 месяцев назад
Webinar - Data Protection in the UK: What Next? - INTRO
Webinar - A New Management System Standard for AI - ISO 42001 - INTRO
Просмотров 2598 месяцев назад
Webinar - A New Management System Standard for AI - ISO 42001 - INTRO
Webinar - ISO 27001 Implementation and Certification - INTRO
Просмотров 1248 месяцев назад
Webinar - ISO 27001 Implementation and Certification - INTRO

Комментарии

  • @imhotep1613
    @imhotep1613 Месяц назад

    Unnecessary and useless background music

  • @Vistainfosecofficial
    @Vistainfosecofficial Месяц назад

    Informative Podcast

  • @DanielThonDengduer
    @DanielThonDengduer 3 месяца назад

    That's amazing professional International Betting APP and it will be a best opportunity for all the beginners please

  • @MacArthurRae-c7j
    @MacArthurRae-c7j 3 месяца назад

    Spencer Court

  • @Vistainfosecofficial
    @Vistainfosecofficial 5 месяцев назад

    For all beginners, 02:12 is very important. Take notes

  • @EdwardAmarh-01
    @EdwardAmarh-01 6 месяцев назад

    Hi, please how do I access the full webinar

  • @fmartinez004
    @fmartinez004 7 месяцев назад

    The background music is distracting

  • @SuneAndersenspe
    @SuneAndersenspe 8 месяцев назад

    crisp n clear!! love the clean English.. no pigon ;-)

  • @aahowlader7342
    @aahowlader7342 8 месяцев назад

    Very useful but background music is so loud! Would be great with no background music 🎼. Thank you

  • @KhakiLuckyLabbot
    @KhakiLuckyLabbot 9 месяцев назад

    Thank you for the material.

  • @Risklearner
    @Risklearner 11 месяцев назад

    Perfect overview of ISO 27001 Risk Management. Thank you so much.

  • @Amberlynn_Reid
    @Amberlynn_Reid 11 месяцев назад

    I support all trans 🏳️‍⚧️

  • @JohnJohnson-ch6xq
    @JohnJohnson-ch6xq Год назад

    Very useful piece

  • @guts4313
    @guts4313 Год назад

    amazing video, complete, clear thank you !

  • @orlalaw9650
    @orlalaw9650 Год назад

    Can you please recommend a solution for Dual Control to meet PCI compliance?

  • @GodFearingPookie
    @GodFearingPookie Год назад

    The bg music makes it hard

  • @maheshwarbanuk4389
    @maheshwarbanuk4389 Год назад

    Not mentioning the clause by name during the explanation, makes this video useless

  • @sbmasonator
    @sbmasonator Год назад

    Helpful video. Bu...somebody buy that guy a new microphone.

  • @alyu9337
    @alyu9337 Год назад

    Great video, which the music wasn’t added

  • @cameronhay7040
    @cameronhay7040 2 года назад

    Great summary. Thank you

  • @yavuz5458
    @yavuz5458 2 года назад

    That is a very very good summary of ISO 27001. I saved for later watchings. I think, it's very useful to renew our knowledges.

  • @deep001007
    @deep001007 2 года назад

    This video is better than the best and it has very useful content

  • @arsalananwar8265
    @arsalananwar8265 2 года назад

    11 new controls introduced in the ISO 27001 2022 revision: A.5.7 Threat intelligence A.5.23 Information security for use of cloud services A.5.30 ICT readiness for business continuity A.7.4 Physical security monitoring A.8.9 Configuration management A.8.10 Information deletion A.8.11 Data masking A.8.12 Data leakage prevention A.8.16 Monitoring activities A.8.23 Web filtering A.8.28 Secure coding

  • @ithink_theniam
    @ithink_theniam 2 года назад

    great video without background music

  • @maheshwarbanuk4389
    @maheshwarbanuk4389 2 года назад

    I had to rewind several times the parts where background music was being played.

  • @ashrafesmail3522
    @ashrafesmail3522 2 года назад

    How to become qualified to work as PCI DSS analyst?

  • @ashrafesmail3522
    @ashrafesmail3522 2 года назад

    How to become qualified to work as PCI DSS analyst?

  • @shlokasmadeeasy
    @shlokasmadeeasy 2 года назад

    Really awesome. Please add more videos on Information security...

  • @gladifineran1664
    @gladifineran1664 2 года назад

    【p】【r】【o】【m】【o】【s】【m】

  • @onlinesaidasa9105
    @onlinesaidasa9105 2 года назад

    Namaste The 12 requirements of PCI DSS are: Install and maintain a firewall configuration to protect cardholder data Do not use vendor-supplied defaults for system passwords and other security parameters Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Use and regularly update anti-virus software or programs Develop and maintain secure systems and applications Restrict access to cardholder data by business need to know Assign a unique ID to each person with computer access Restrict physical access to cardholder data Track and monitor all access to network resources and cardholder data Regularly test security systems and processes Maintain a policy that addresses information security for all personnel

  • @ashrafesmail3522
    @ashrafesmail3522 2 года назад

    Please I want to contact you for a very important thing

  • @AutomateTopicalAuthority
    @AutomateTopicalAuthority 2 года назад

    Great info, please reduce the bg music by about 60% or remove.

  • @AutomateTopicalAuthority
    @AutomateTopicalAuthority 2 года назад

    music is too loud

  • @NitinGupta-uj3lm
    @NitinGupta-uj3lm 2 года назад

    Nice summarisation.

  • @thousandsunny2572
    @thousandsunny2572 2 года назад

    Great!

  • @vuyanidaweti7384
    @vuyanidaweti7384 2 года назад

    Great I really enjoyed this, thank you

  • @niyatiburghate6893
    @niyatiburghate6893 2 года назад

    Fantastic video, crisp n clear!! Thanks

  • @chadparsons50
    @chadparsons50 2 года назад

    Very well done presentation!

  • @chadparsons50
    @chadparsons50 2 года назад

    Excellent, easy to understand, presentation. Thank you!

  • @ratnesh12100
    @ratnesh12100 2 года назад

    Without background music, would be better

  • @rachaellevermore
    @rachaellevermore 2 года назад

    Really useful Lisa - thank you!

  • @lifesacardgame6454
    @lifesacardgame6454 2 года назад

    Thank you. Great summary.

  • @demetridoes
    @demetridoes 2 года назад

    Great video, helped me a lot! However, the background music is extremely annoying. Thanks for informative video!