Stuart Barker
Stuart Barker
  • Видео 339
  • Просмотров 298 529

Видео

ISO 27001 Management of Technical Vulnerabilities | Annex A 8.8 | Explained
Просмотров 165Месяц назад
ISO 27001 Management of Technical Vulnerabilities | Annex A 8.8 | Explained
ISO 27001 Protection Against Malware | Annex A 8.7 | Explained
Просмотров 216Месяц назад
ISO 27001 Protection Against Malware | Annex A 8.7 | Explained
ISO 27001 Capacity Management | Annex A 8.6 | Explained
Просмотров 174Месяц назад
ISO 27001 Capacity Management | Annex A 8.6 | Explained
ISO 27001 Secure Authentication | Annex A 8.5 | Explained
Просмотров 1082 месяца назад
ISO 27001 Secure Authentication | Annex A 8.5 | Explained
ISO 27001 Access To Source Code | Annex A 8.4 | Explained
Просмотров 1192 месяца назад
ISO 27001 Access To Source Code | Annex A 8.4 | Explained
ISO 27001 Information Access Restriction | Annex A 8.3 | Explained
Просмотров 872 месяца назад
ISO 27001 Information Access Restriction | Annex A 8.3 | Explained
ISO 27001 Privileged Access Rights | Annex A 8.2 | Explained
Просмотров 1672 месяца назад
ISO 27001 Privileged Access Rights | Annex A 8.2 | Explained
ISO 27001 User Endpoint Devices | Annex A 8.1 | Explained
Просмотров 1722 месяца назад
ISO 27001 User Endpoint Devices | Annex A 8.1 | Explained
ISO 27001 Secure Disposal or Re Use of Equipment | Annex A 7.14 | Explained
Просмотров 802 месяца назад
ISO 27001 Secure Disposal or Re Use of Equipment | Annex A 7.14 | Explained
ISO 27001 Equipment Maintenance | Annex A 7.13 | Explained
Просмотров 762 месяца назад
ISO 27001 Equipment Maintenance | Annex A 7.13 | Explained
ISO 27001 Cabling Security | Annex A 7.12 | Explained
Просмотров 752 месяца назад
ISO 27001 Cabling Security | Annex A 7.12 | Explained
ISO 27001 Supporting Utilities | Annex A 7.11 | Explained
Просмотров 862 месяца назад
ISO 27001 Supporting Utilities | Annex A 7.11 | Explained
ISO 27001 Storage Media | Annex A 7.10 | Explained
Просмотров 862 месяца назад
ISO 27001 Storage Media | Annex A 7.10 | Explained
ISO 27001 Security of Assets Off Premises | Annex A 7.9 | Explained
Просмотров 1142 месяца назад
ISO 27001 Security of Assets Off Premises | Annex A 7.9 | Explained
ISO 27001 Equipment Siting and Protection | Annex A 7.8 | Explained
Просмотров 932 месяца назад
ISO 27001 Equipment Siting and Protection | Annex A 7.8 | Explained
ISO 27001 Clear Desk and Clear Screen | Annex A 7.7 | Explained
Просмотров 1352 месяца назад
ISO 27001 Clear Desk and Clear Screen | Annex A 7.7 | Explained
ISO 27001 Working In Secure Areas | Annex A 7.6 | Explained
Просмотров 702 месяца назад
ISO 27001 Working In Secure Areas | Annex A 7.6 | Explained
ISO 27001 Protecting Against Physical and Environmental Threats | Annex A 7.5 | Explained
Просмотров 1032 месяца назад
ISO 27001 Protecting Against Physical and Environmental Threats | Annex A 7.5 | Explained
ISO 27001 Physical Security Monitoring | Annex A 7.4 | Explained
Просмотров 1082 месяца назад
ISO 27001 Physical Security Monitoring | Annex A 7.4 | Explained
ISO 27001 Securing Offices, Rooms and Facilities | Annex A 7.3 | Explained
Просмотров 1432 месяца назад
ISO 27001 Securing Offices, Rooms and Facilities | Annex A 7.3 | Explained
ISO 27001 Physical Entry Controls | Annex A 7.2 | Explained
Просмотров 1342 месяца назад
ISO 27001 Physical Entry Controls | Annex A 7.2 | Explained
ISO 27001 Physical Security Perimeters | Annex A 7.1 | Explained
Просмотров 2142 месяца назад
ISO 27001 Physical Security Perimeters | Annex A 7.1 | Explained
ISO 27001 Information Security Event Reporting | Annex A 6.8 | Explained
Просмотров 862 месяца назад
ISO 27001 Information Security Event Reporting | Annex A 6.8 | Explained
ISO 27001 Remote Working | Annex A 6.7 | Explained
Просмотров 762 месяца назад
ISO 27001 Remote Working | Annex A 6.7 | Explained
ISO 27001 Confidentiality or Non Disclosure Agreements | Annex A 6.6 | Explained
Просмотров 662 месяца назад
ISO 27001 Confidentiality or Non Disclosure Agreements | Annex A 6.6 | Explained
ISO 27001 Responsibilities After Termination or Change of Employment | Annex A 6.5 | Explained
Просмотров 802 месяца назад
ISO 27001 Responsibilities After Termination or Change of Employment | Annex A 6.5 | Explained
ISO 27001 Disciplinary Process | Annex A 6.4 | Explained
Просмотров 1012 месяца назад
ISO 27001 Disciplinary Process | Annex A 6.4 | Explained
ISO 27001 Information security awareness, education and training | Annex A 6.3 | Explained
Просмотров 1542 месяца назад
ISO 27001 Information security awareness, education and training | Annex A 6.3 | Explained
ISO 27001 Terms and Conditions of Employment | Annex A 6.2 | Explained
Просмотров 812 месяца назад
ISO 27001 Terms and Conditions of Employment | Annex A 6.2 | Explained

Комментарии

  • @SujithaSadagopan
    @SujithaSadagopan 3 дня назад

    please continue and complete the rest of the Technological controls. Its very useful

    • @StuartBarker
      @StuartBarker 3 дня назад

      Yes - on the plan :) they take up a bit of time but I am nearly there. Thank you for the feedback. I hope to do more this week! Keep watching. 🙏

    • @SujithaSadagopan
      @SujithaSadagopan 3 дня назад

      @@StuartBarker Thanks for the response. Sure. Waiting for the videos.

  • @armandtaheri7504
    @armandtaheri7504 4 дня назад

    like if Stuart Barker is your new favorite youtuber 😄

  • @onyerekene7586
    @onyerekene7586 4 дня назад

    Thanks so much for this. Very useful information. I've just purchased the template.

    • @StuartBarker
      @StuartBarker 3 дня назад

      That is great - the main toolkit is currently on offer and worth a look. Thank you. 🙏

  • @dbellconsulting
    @dbellconsulting 6 дней назад

    Good video Stuart. A question I have relates to your comment "We have to audit everything at least once". In your experience, are you referring to 'at least once each 3-year certification period', as opposed to once each year?

    • @StuartBarker
      @StuartBarker 6 дней назад

      Every calendar year between external audit cycles. I have seen where people do once per 3 year cycle and get an observation, minor or major non conformity. I appreciate this doesnt seem consistent but it is auditor dependant. The best practice approach would be once per calendar year minimum but I have a video on audit planning that explains in more detail - this link should take you direct to the relevant section - ruclips.net/video/hz_hPt4DZvw/видео.html

    • @StuartBarker
      @StuartBarker 6 дней назад

      Sorry the relevant section is 4 minutes and 9 seconds.

    • @dbellconsulting
      @dbellconsulting 5 дней назад

      @@StuartBarker Yes, I agree that the internal audit program should be implemented regularly between external CAB audits. Perhaps I should have put my question more clearly - would you suggest that the entire ISMS (processes and controls) are to be audited every year, or a sampled approach is taken over the 3-year certification cycle on the basis of process criticality or risk exposure?

    • @StuartBarker
      @StuartBarker 4 дня назад

      @dbellconsulting - the video that I link goes into the nuances of it but ISO 27001 is a risk based system so the audit program is based on risk. A good starting point is to audit the entire ISMS every year as I have seen that the ISMS itself often gets overlooked and I have seen auditors raise that as a non conformity. Start on the basis of once a year for the entire ISMS and with the knowledge that certain parts of the ISMS may require auditing more than once in that one year cycle. The video on audit planning sets out the exact way I would go about it and the variations / exceptions and considerations to take. For me, once per year would be the minimum to ensure an effective management system - if I was talking broad brush. If it is right for you to do a sampled approached over the 3 year certification cycle based on your risk and you are comfortable you can justify the approach then that should be fine but I would treat this more as an exception than the rule. 🙏

  • @hamidahjusoh5032
    @hamidahjusoh5032 13 дней назад

    thank you for your sharing.

  • @thejessicaduke
    @thejessicaduke 15 дней назад

    Is the incident and corrective action log used to also capture/record nonconformities identified during audits?

    • @StuartBarker
      @StuartBarker 15 дней назад

      yes. It is one way to do it and the way I do it. 🙏

    • @thejessicaduke
      @thejessicaduke 14 дней назад

      @ thank you so much

  • @desireideas
    @desireideas 29 дней назад

    Hey, Could you please make a video on control: 8.10 Information deletion, specially when the organization has already implemented a retention schedule to comply with the process. Need to know few ideas to implement this. Thankyou

    • @StuartBarker
      @StuartBarker 29 дней назад

      Working through them and it coming soon but you can jump on a free weekly clinic to ask me questions and run through. Website menu / learn / iso 27001 clinic - to book

  • @Lahori369
    @Lahori369 Месяц назад

    Excellent job, dear sir. May God bless you from Pakistan.

  • @GileHub
    @GileHub Месяц назад

    Hi, I'm curious, you say that the 2022 update requires the 'Context of the Organisation' document to explicitly show how the organisation is 'satisfying the requirement', but in the template this column is only used from the 'Interested Parties' table. It is not included in the 'Internal' and 'External issues' tables - do we not also need to show this in these sections? Or is it that this is expanded upon in the Risk Register enough?

    • @StuartBarker
      @StuartBarker Месяц назад

      This was included in the 2022 update to the template and is in the latest toolkit to make it explicit. I even pre fill it with examples. The previous assumption was people would know how the ISMS meets requirements but you cannot assume anything so I updated it to make it more explicit. Thanks for watching and good spot that many would not. Latest template and toolkit = it is included.

    • @GileHub
      @GileHub Месяц назад

      @@StuartBarker thank you. I must be working from the old version. You've reminded me to look at the updates. thank you. Your product is great. I'm getting through it!

  • @jack_b_za6415
    @jack_b_za6415 Месяц назад

    So I have a question: When you say software register, as an MSSP we resell software to clients do we need to keep this as part of our software register? i.e. licenses for clients? software for clients?

    • @StuartBarker
      @StuartBarker Месяц назад

      @jack_b_za6415 You can jump on a free weekly clinic or grab a 1 to 1 as hard to answer in small comments but I would expect that you have a register of all your clients, what software they have purchased, the licenses that go with that. THEY will have a requirement under the intellectual property control to evidence licensing and software and if they rely on you they will expect that you can evidence it. Which alludes to what this control is about. Do you know, in total, what you have in place for your ISO 27001 scope ( I narrow it here but really you would want to know EVERYTHING you have ). The control wants what YOU have but it clearly makes sense, based on what you tell me and the requirements your clients have that you have this for clients and what you sell also. Hope makes sense - jump on a clinic or call to chat through if you need more.

  • @KylaSkosana-g3u
    @KylaSkosana-g3u Месяц назад

    going to start applying the audit compliance report on my completed tasks/audit so i can keep track on what has been applied. Thank you.

  • @KylaSkosana-g3u
    @KylaSkosana-g3u Месяц назад

    writing my ISO27001:20222 Practitioner exam in 3days and I came through your ISO27001 series- I'm hooked and everything is explain clearly.

    • @StuartBarker
      @StuartBarker Месяц назад

      Thank you and good luck with the exam. Let me know how you found it. 🙏

  • @SudhakarSuresh-z3i
    @SudhakarSuresh-z3i Месяц назад

    What is the difference between 5.29 and 5.30. Because these two seems to be same, could you please provide the clarification.

    • @StuartBarker
      @StuartBarker Месяц назад

      5.29 - hightable.io/iso-27001-annex-a-5-29-information-security-during-disruption/ 5.30 - hightable.io/iso-27001-annex-a-5-30-ict-readiness-for-business-continuity/ 5.29 - what are your information security requirements during a disruption and how do they differ from production 5.30 - what ICT disaster recovery do you have in place

  • @Z3kyTw0
    @Z3kyTw0 Месяц назад

    excellent explanation thank you!

  • @lecompt
    @lecompt Месяц назад

    We are a very small company with 10 employees total. Would the same 3 leadership people be assigned to all these roles or do I remove some of roles? For instance, I'm the CEO and probably the Information Security Manager.

    • @StuartBarker
      @StuartBarker Месяц назад

      @lecompt - A person can hold more than one role. This video is the explanation and help - > ruclips.net/video/_CP7vr-8MYk/видео.html

  • @RandomVideos-hm3kg
    @RandomVideos-hm3kg Месяц назад

    audio bad

    • @StuartBarker
      @StuartBarker Месяц назад

      Appreciate the feedback. It is taken directly from a Teams recording of a real life session so yeah, not great but the content hopefully is on point. Appreciate the feedback though - check out the other actual training and implementation videos that are in 4k with dolby surround. 🙏

    • @RandomVideos-hm3kg
      @RandomVideos-hm3kg Месяц назад

      @@StuartBarker thank you The content is good. But i haven't Completed all the parts yet

  • @FunkmetalRulez
    @FunkmetalRulez Месяц назад

    Your content is fantastic. A great help get a good perspective on the ISO 27001 implementation.

    • @StuartBarker
      @StuartBarker Месяц назад

      I appreciate that. Thank you. Makes doing them worth while if they are helping people. 🙏

  • @uwehusmann1417
    @uwehusmann1417 Месяц назад

    Hi Stuart, thank you so much for all your great content and easy to follow examples. Just to be sure: i think you might have missed a "2" in your policy in chapter 3.3 when referencing 27002:2022 Clause 5.3. Shouldn't it be "Clause 5.23" since 5.3 deals with the segregation of duties?

    • @StuartBarker
      @StuartBarker Месяц назад

      I think you are probably correct. I get caught up in the moment but hopefully it helped. You certainly know your onions! :) 🙏

  • @onyerekene7586
    @onyerekene7586 Месяц назад

    Very useful information. Thank you very much!

  • @nguyenngocquan3312
    @nguyenngocquan3312 Месяц назад

    thank u so much, that all i need 🎉

    • @StuartBarker
      @StuartBarker Месяц назад

      Hey, happy to help! thanks for the feedback 🙏

  • @nasseral-maidhan1587
    @nasseral-maidhan1587 2 месяца назад

    US DOD 5220.22-m (3 passes or 7 passes).

  • @albertocalleros5981
    @albertocalleros5981 2 месяца назад

    Short, informative, to the point. I really enjoy your videos. :)

  • @PKTraceur
    @PKTraceur 2 месяца назад

    This stuff is a headache for more technical and not so risk/management oriented people like me, this is very well put and has good examples.

  • @victorfrancis1378
    @victorfrancis1378 2 месяца назад

    thank you so much, exactly what i was looking for

  • @klinktastic
    @klinktastic 2 месяца назад

    @stuart barker - if I watch all these videos, can I claim I'm ISO 27001 lead auditor/implementer?

    • @StuartBarker
      @StuartBarker 2 месяца назад

      I watched George Clooney back in the day in Batman. It did not make me Batman nor sadly George Clooney but inside, you know, and I know, I really am Batman. So maybe ....

  • @Joelrao77
    @Joelrao77 2 месяца назад

    Hi Stuart Can you please share the link to this deployment guide? Thank you

    • @StuartBarker
      @StuartBarker 2 месяца назад

      Of course: hightable.io/how-to-write-deploy-and-implement-iso-27001-policies/

  • @klinktastic
    @klinktastic 2 месяца назад

    i'm enjoying these daily hits on the various controls...very good stuff

  • @asifali78622
    @asifali78622 2 месяца назад

    Great! Thanks for sharing. Appreciated.

  • @paul4561
    @paul4561 2 месяца назад

    Hi Stuart, how difficult is it to get this kind of work? I have been working in different areas of IT for years. I have a Msc in Cyber, CISSP. I worked as an information security manager for a large organisation for 2+ years. Now recently moved to a Cybersecurity GRC role for group of universities. I am at the early stages of the ISMS and it a great learning experience, I am getting to build it out and right in the mix of it. Lots of cloud infra. I would love to at some point have my own company and do this type of work.

    • @StuartBarker
      @StuartBarker 2 месяца назад

      @paul4561 - you can book a free 1 to 1 with me on hightable.io - I have previously built and sold a company doing this although now I give knowledge away for free. Also this video is from a consultant coaching programme I do - ruclips.net/video/HojVRKC6FPU/видео.html - it is doable.

    • @paul4561
      @paul4561 2 месяца назад

      @@StuartBarker Thank you, must get chatting to you :)

  • @LoverAngelo
    @LoverAngelo 2 месяца назад

    Is it possible to only buy "The ISO 27001:2022 ISMS - audit worksheet"? it is accessible just in ISO 27001 Gap Analysis and Audit Tool whole package :(

    • @StuartBarker
      @StuartBarker 2 месяца назад

      Linkin with me and I can share with you... 👍

    • @LoverAngelo
      @LoverAngelo 2 месяца назад

      @@StuartBarker Thank you so much. How can I contact you? email, LinkedIn chat, or other ways?

  • @zzzzIvanzzz
    @zzzzIvanzzz 2 месяца назад

    Short and simple, great work! Thank you for sharing.

  • @FloridaInvestor
    @FloridaInvestor 2 месяца назад

    Is this a good series to learn to land a job?

    • @StuartBarker
      @StuartBarker 2 месяца назад

      Depends what kind of job you want there Florida Investor ! I would say it is information that you would pay someone to train you on and is based on 30+ years experience but only you can judge its value. As for landing a job ... I wanted to be a stripper but I don't think it's going to help me with that... I guess it all about context 🙏

  • @maceo4100
    @maceo4100 2 месяца назад

    I've just bought it. Finally a reasonable risk register. Good Job!

  • @pauldevine6086
    @pauldevine6086 2 месяца назад

    Great Discussion, love your presentation style and love your ISO pack!

  • @RyanPST88
    @RyanPST88 3 месяца назад

    Hi Stuart, this document example focuses on Cloud Supplier, just wondering would we not need to talk about the actually Cloud security we have in place, firewalls, anti-virus and so on?

    • @StuartBarker
      @StuartBarker 2 месяца назад

      Yes Ryan. This is part of the overall puzzle. This policy meets the requirements for having a cloud services policy and the requirements for cloud providers but remember that the standard is made up of many policies and Annex A controls that address specifics such as access control, network security, physical security, anti malware and much much more. The points you raise are addressed, but not here. Which out of context may seem strange but we are creating building blocks to create a house. What ever house you need and want. You can join the Q and A or drop me a 1 to 1 and I can cover for you in more detail than the comments allow. 🙏

    • @StuartBarker
      @StuartBarker 2 месяца назад

      One of many additional videos that support this area that will add some context to this 'how to' video - ruclips.net/video/pD9xeH-NlM8/видео.html

  • @nasseral-maidhan1587
    @nasseral-maidhan1587 3 месяца назад

    👍

  • @orancohen5576
    @orancohen5576 3 месяца назад

    This is an excellent foundation. Thank you! I'm learning a ton. Context is everything!

  • @venkakula2594
    @venkakula2594 3 месяца назад

    I never thought I'd get fuckin iso27001 shorts....

    • @StuartBarker
      @StuartBarker 3 месяца назад

      Your / You're welcome ☺️

    • @venkakula2594
      @venkakula2594 3 месяца назад

      @@StuartBarker Hahaha, so fair man, so fair.

  • @JossOrtan
    @JossOrtan 3 месяца назад

    Great breakdown on implementing ISO 27001 Annex A 5.7 for threat intelligence! What are some common pitfalls to avoid during the audit?

    • @StuartBarker
      @StuartBarker 3 месяца назад

      Thank you - I cover what you need in the blog that goes with the video - it is here for reference - hightable.io/iso-27001-annex-a-5-7-threat-intelligence/ 🙏

  • @diegogomes5837
    @diegogomes5837 3 месяца назад

    Obrigado!

  • @diegogomes5837
    @diegogomes5837 3 месяца назад

    Muito obrigado!

  • @diegogomes5837
    @diegogomes5837 3 месяца назад

    Muito obrigado!

  • @diegogomes5837
    @diegogomes5837 3 месяца назад

    I love your work!

  • @mohammedhussainshaikh7991
    @mohammedhussainshaikh7991 3 месяца назад

    Thanks for explaining concept so easily

  • @mohammedhussainshaikh7991
    @mohammedhussainshaikh7991 3 месяца назад

    Thanks for explaining concept so easily

  • @nasseral-maidhan1587
    @nasseral-maidhan1587 3 месяца назад

    Thank you 👍

  • @Bcc074
    @Bcc074 3 месяца назад

    HI Stuart. Thank you for this very informative series. You stated that if an organization does not do DevOps then no need to deploy a DevOps policy. Would it be advisable to implement a policy that states the organization will not be engaged in DevOps practices or is it better to not create a DevOps policy altogether? Thanks.

    • @StuartBarker
      @StuartBarker 3 месяца назад

      Read this blog - hightable.io/iso-27001-when-you-have-no-office/ - but substitute dev ops for physical security. It is the same approach for you. Let me know if that not answer or you have questions but I think it will give you what you need 🙏

    • @Bcc074
      @Bcc074 3 месяца назад

      @@StuartBarker This helps. Thank you again for your help.

    • @Bcc074
      @Bcc074 3 месяца назад

      @@StuartBarker That was helpful. Thank you.

  • @ShreyasP-c2q
    @ShreyasP-c2q 3 месяца назад

    Where can i find the template of this document ?

    • @StuartBarker
      @StuartBarker 3 месяца назад

      You can find it here: hightable.io/product/iso-27001-annex-a-5-2-information-security-roles-and-responsibilities-template/. 🙏🙏🙏🙏

  • @madhankumar1811
    @madhankumar1811 4 месяца назад

    excellent elaborate explanation videos Keep up the great work Mr.Stuart Barker

  • @adagal13
    @adagal13 4 месяца назад

    This toolkit is awesome! So much included for a senior admin like me who is implementing an ISO 27001 aligned ISMS. Highly recommended as it's a fraction of the price you are going to look at paying for other services of this value.