Can someone explain how do you use iso to check if controls are in place, same with nist and soc etc and what trainings are best to get goood at each

like
Posting as :
works at
You are currently posting as works at

ISO is a standard and the company will normally hire an auditor to assess the company's polices, procedures and processes against the standard to see if the company is complaint, if the auditor certifies the company as compliant the company can say that it is ISO certifed so it gives some assurance to customers and other third-parties. Service Organization Control (SOC) reports list the objective and the controls the organization has in place to meet the objectives. For a Type I SOC report the auditor will only test the design for a Type II report the auditor will test the operating effectiveness.

Or you would include them in your TPRM program

They are frameworks and usually people learn on the job. Getting the standard cyber certs should be all the background you need.

Have your hard of CTPRA?

Related Posts

Does anyone ever redeem Marriott points for gift cards? Is it worth it?

like

Klick - would you go? Why or why not?

Anyone work for VMware who can provide a referral for a Senior Project Manager roles?

like

Can my spouse change her job while green card application is pending. I'm the primary applicant and both my I140 and I485 are pending.

She is currently working on an L2S which is also up for renewal. On similar terms, would her job change have any impact to her L2S renewal application, assuming it's applied and pending with USCIS by that time.

like

Hiring @Trianz for mentioned positions. Please message me with the Role name and I will share the detailed job description. Thank you.

Post Photo
like

The president of Nintendo America is named Bowser. Wat.

likehelpfulfunny

I work in Nj at a pharmaceutical company and have been there for the past 4 years supporting a VP and currently at 77k a year and it’s not enough. Going to start interviewing elsewhere and want to get an idea of what starting salaries you all are at and what I should ask for. Any advice ?

like

Hey fishes, what is the in hand salary in PWC India for 9lpa fixed salary?

like

Any 🐠 looking for a place to stay in Boston this winter? I am taking advantage of 100% remote work and going to Utah. Looking to rent out my furnished 2 BR 2Bath apartment, downtown- water view of the harbor next to the aquarium.
$4k a month (renting at cost)

Post Photo
like

Had my virtual on-site for an S&O L3 role 3.5 weeks ago (NYC, 5 YOE). I haven’t heard back on a decision yet, and was wondering how long it typically takes? I also know that I was one of the very first candidates to interview for this specific role, and there are atleast 2 more people scheduled for onsites. Does the recruiter typically wait for all candidates to finish their onsites before communicating a decision? Or if I haven’t heard back yet, it’s probably a reject?

like
like

Thoughts on Viibryd? Im on my 4th week and I feel like it’s affecting my cognition. I’m finding it difficult connecting the dots as I carry out my job and it’s getting me worried.

like

Hi fishes,

I found different user login related bugs in a website that hamper the user experience.

What is the correct procedure to report those bugs?

Also, can there be any potential scope to get bug bounty for the same?

How to approach this?

I'm planning to send an email with the details of the bugs to the customer care and feedback email of that website.

Thanks a lot.

like

Anyone else extreme ? Love the fit life and sometimes will do 2 a days and be ok with eating one meal, but other times will spend the day barely moving and eating on my sofa. Can’t escape fatty life

like

Did anyone from your past tell you you wouldnt make it as a lawyer? Did you ever rub it in their face later that you in fact did?? 😂

like

Bali recommendations on things to do?

like

Anyone with insight on Tyson Mendes?

like

Thoughts on Snowflake? Had a brief intro on the architecture and looks like a scalable solution for the future. Thoughts?

like

Linux Academy or acloudguru for studying/passing Solutions Architect Pro Exam?

like
like

Additional Posts in Cyber Security Bowl

What other professional services firms have people who have technical skills. Most the people I work with are security paper pushers who couldn’t tell you basic security shit.

like

Always bragging about how awesome they are. Awesome people dont brag. They just are

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

As more and more companies institute a work from home policy, I think it will gradually become the norm. As a 28 year old man who wants to settle down soon, which city would you recommend I look into, assuming me and my partner can work from home? I work in Cybersecurity so would prefer to be closer to the jobs in my field without having to live in the same city.

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

Joining a group that specializes in incident response. Any recommendations on things I can do this summer to prepare on fundamentals/certs?

like

CCSP (cloud security certification) is it worth to do ?

like

Anyone here invested in any cyber etf? if yes which one is it?

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Georgia Tech Cybersecurity masters or the analytics masters? Currently in a cyber role at Deloitte. I was thinking it might be better to do the analytics master and get a CISSP. I feel like there is more value in the cissp than a MS cybersecurity

like

Anyone else at CyberArk Impact this week? Anything exciting going on?

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Has anyone made the move from cyber security at the Big4 to cyber security for media companies? For example Disney or Warner Bros.

How did you manage it?

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Any tips or tricks for CSX certification?

like

Hey all, I have been working in Identity and access management space at EY for past 4 years. Need help with understanding best exit opportunities?

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal