<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Guiding principles in Welcome</title>
    <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46818#M2021</link>
    <description>&lt;P&gt;If they're already familiar with the ISO standards related to the different manufacturing processes, it may not be a hard sell if you wanted to start the conversation with 27001.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you wanted to throw a quick slide show together about what you listed, I'd recommend building it off of the CIS Controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisecurity.org/controls/cis-controls-list/" target="_blank"&gt;The 18 CIS Controls (cisecurity.org)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 13:34:16 GMT</pubDate>
    <dc:creator>tmekelburg1</dc:creator>
    <dc:date>2021-08-05T13:34:16Z</dc:date>
    <item>
      <title>Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46814#M2020</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a 400 staff client, a manufacturing company. This client is far away from (ISO27001) certification. I want to start small by presenting security guiding principles; e.g. use least privilages, avoid using generic accounts, avoid giving persons access rights on CI's (use security groups), use netwerksegmentation, harden servers, keep servers up to date, CIA etc. This should fit on&amp;nbsp;1 page.&lt;BR /&gt;These are general principle's, so it does not describe "how" and "scope".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there somebody who has listed these principles already and is willing to share?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:57:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46814#M2020</guid>
      <dc:creator>Cees</dc:creator>
      <dc:date>2023-10-09T09:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46818#M2021</link>
      <description>&lt;P&gt;If they're already familiar with the ISO standards related to the different manufacturing processes, it may not be a hard sell if you wanted to start the conversation with 27001.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you wanted to throw a quick slide show together about what you listed, I'd recommend building it off of the CIS Controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisecurity.org/controls/cis-controls-list/" target="_blank"&gt;The 18 CIS Controls (cisecurity.org)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 13:34:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46818#M2021</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-08-05T13:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46825#M2022</link>
      <description>&lt;P&gt;Depend on your audience and readers.&lt;/P&gt;&lt;P&gt;NIST 800 SP 160 volume 1 has appendix F for design principle for security (but that's for security engineering), pick the most important for you.&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1.pdf" target="_blank"&gt;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 18:53:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46825#M2022</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2021-08-05T18:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46831#M2023</link>
      <description>Appendix F gives me inspiration for making a 1 page summery. thanks</description>
      <pubDate>Fri, 06 Aug 2021 07:49:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46831#M2023</guid>
      <dc:creator>Cees</dc:creator>
      <dc:date>2021-08-06T07:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46833#M2024</link>
      <description>&lt;P&gt;you are welcome. Glad that it give you a starting point.&lt;/P&gt;&lt;P&gt;NIST actually has many good resource and practice, but the problem is you need to know where to find, which SP is taking care of what and spend time on them.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 09:30:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46833#M2024</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2021-08-06T09:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46837#M2025</link>
      <description>&lt;P&gt;You could start by simple by ensuring the essentials were in place:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ncsc.gov.uk/files/NCSC_A5_Small_Business_Guide_v4_OCT20.pdf" target="_blank"&gt;https://www.ncsc.gov.uk/collection/small-business-guidehttps://www.ncsc.gov.uk/files/NCSC_A5_Small_Business_Guide_v4_OCT20.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ncsc.gov.uk/collection/10-steps" target="_blank"&gt;https://www.ncsc.gov.uk/collection/10-steps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ncsc.gov.uk/files/2021-10-steps-to-cyber-security-infographic.pdf" target="_blank"&gt;https://www.ncsc.gov.uk/files/2021-10-steps-to-cyber-security-infographic.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's important not to get lost in the detail and overlook something essential.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 10:20:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46837#M2025</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2021-08-06T10:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security Guiding principles</title>
      <link>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46842#M2026</link>
      <description>Very interesting. It looks like the Statement of Applicability of the ISO 27001. The excel gives a great overview,</description>
      <pubDate>Fri, 06 Aug 2021 11:29:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Security-Guiding-principles/m-p/46842#M2026</guid>
      <dc:creator>Cees</dc:creator>
      <dc:date>2021-08-06T11:29:39Z</dc:date>
    </item>
  </channel>
</rss>

