<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ISO 27001 &#38; BS 25999</title>
	<atom:link href="http://blog.iso27001standard.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.iso27001standard.com</link>
	<description>Leading blog on ISO 27001 &#38; BS 25999-2. Written by Dejan Kosutic.</description>
	<lastBuildDate>Mon, 07 May 2012 17:24:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Top 10 information security blogs</title>
		<link>http://blog.iso27001standard.com/2012/05/07/top-10-information-security-blogs/</link>
		<comments>http://blog.iso27001standard.com/2012/05/07/top-10-information-security-blogs/#comments</comments>
		<pubDate>Mon, 07 May 2012 17:24:58 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Information security]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1998</guid>
		<description><![CDATA[
			
		
		ShareThere is a huge amount of information about information security on the Internet, so it is really difficult to stay informed about really relevant stuff. This is why I made this list – I wanted to offer a list of independent, expertly written and up-to-date blogs that will keep you right on track.
The blogs are [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/05/07/top-10-information-security-blogs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The documentation myth &#8211; Why the templates are not enough?</title>
		<link>http://blog.iso27001standard.com/2012/04/24/the-documentation-myth-why-the-templates-are-not-enough/</link>
		<comments>http://blog.iso27001standard.com/2012/04/24/the-documentation-myth-why-the-templates-are-not-enough/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 09:17:05 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[document management]]></category>
		<category><![CDATA[HR management]]></category>
		<category><![CDATA[information security policy]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[training & awareness]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1992</guid>
		<description><![CDATA[
			
		
		ShareI noticed that many people running ISO 27001 projects who have downloaded documentation templates think &#8220;I have the templates now – the rest is easy. I&#8217;ll write a few documents, show them to auditor, and it&#8217;ll be over in a few days&#8221;.
Unfortunately, it&#8217;s not that easy. Here&#8217;s why:
1. Writing the documentation requires time and effort
You [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/04/24/the-documentation-myth-why-the-templates-are-not-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 27001 control objectives &#8211; Why are they important?</title>
		<link>http://blog.iso27001standard.com/2012/04/10/iso-27001-control-objectives-why-are-they-important/</link>
		<comments>http://blog.iso27001standard.com/2012/04/10/iso-27001-control-objectives-why-are-they-important/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 07:48:00 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27004]]></category>
		<category><![CDATA[measurement]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1986</guid>
		<description><![CDATA[
			
		
		SharePeter Drucker (one of the most influential thinkers on the subject of management theory) said &#8220;What gets measured gets managed&#8221;. The same goes for information security – if you don&#8217;t know how well you are doing, you&#8217;ll have a very difficult time steering your information security in the desired direction.
And it is exactly this &#8216;desired [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/04/10/iso-27001-control-objectives-why-are-they-important/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 27001 certification for persons vs. organizations</title>
		<link>http://blog.iso27001standard.com/2012/03/26/iso-27001-certification-for-persons-vs-organizations/</link>
		<comments>http://blog.iso27001standard.com/2012/03/26/iso-27001-certification-for-persons-vs-organizations/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 16:55:02 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[management systems]]></category>
		<category><![CDATA[training & awareness]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1981</guid>
		<description><![CDATA[
			
		
		ShareVery often when I deliver free webinars on the topic of ISO 27001 certification, I notice that quite many people expect help with their personal certification related to ISO 27001 while the webinar is focused on certification of organizations.
This kind of misunderstanding is not entirely unexpected since many certifications in the security domain (e.g. CISSP, [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/03/26/iso-27001-certification-for-persons-vs-organizations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons learned from ISO 27001 implementation</title>
		<link>http://blog.iso27001standard.com/2012/03/12/lessons-learned-from-iso-27001-implementation/</link>
		<comments>http://blog.iso27001standard.com/2012/03/12/lessons-learned-from-iso-27001-implementation/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 15:48:35 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 9001]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[training & awareness]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1512</guid>
		<description><![CDATA[
			
		
		ShareMany readers of this blog asked me to present a real-life experience of ISO 27001 implementation in a company. Since I would be too subjective if I started writing my own impressions, I decided to interview my clients – Dragomir Perica and Ivancica Ljubic from Dabar informatika d.o.o., a company specialized in banking software development, [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/03/12/lessons-learned-from-iso-27001-implementation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to become ISO 27001 Lead Auditor</title>
		<link>http://blog.iso27001standard.com/2012/02/27/how-to-become-iso-27001-lead-auditor/</link>
		<comments>http://blog.iso27001standard.com/2012/02/27/how-to-become-iso-27001-lead-auditor/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 18:37:50 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[internal audit]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[training & awareness]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1506</guid>
		<description><![CDATA[
			
		
		ShareMany people think that just by attending the ISO 27001 Lead Auditor Course they have become the ISO 27001 Lead Auditor. Well, this is not entirely true.
This article will show the steps you need to take if you want to work as an auditor for a certification body. If you want to work as an [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/02/27/how-to-become-iso-27001-lead-auditor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why is residual risk so important?</title>
		<link>http://blog.iso27001standard.com/2012/02/13/why-is-residual-risk-so-important/</link>
		<comments>http://blog.iso27001standard.com/2012/02/13/why-is-residual-risk-so-important/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 16:21:42 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[risk treatment]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1501</guid>
		<description><![CDATA[
			
		
		ShareTerm &#8216;residual risk&#8217; is mandatory in the risk management process according to ISO 27001, but is unfortunately very often used without appreciating the real meaning of the concept.
What is residual risk?
According to ISO 27001, residual risk is &#8220;the risk remaining after risk treatment&#8221;.
Here is how it works: first you have to identify the risks, and [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/02/13/why-is-residual-risk-so-important/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is the difference between Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?</title>
		<link>http://blog.iso27001standard.com/2012/01/30/what-is-the-difference-between-recovery-time-objective-rto-and-recovery-point-objective-rpo/</link>
		<comments>http://blog.iso27001standard.com/2012/01/30/what-is-the-difference-between-recovery-time-objective-rto-and-recovery-point-objective-rpo/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 17:01:03 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[BS 25999-2]]></category>
		<category><![CDATA[Business continuity]]></category>
		<category><![CDATA[business continuity strategy]]></category>
		<category><![CDATA[business impact analysis]]></category>
		<category><![CDATA[recovery point objective]]></category>
		<category><![CDATA[recovery time objective]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1495</guid>
		<description><![CDATA[
			
		
		ShareThey are both essential elements of business continuity, and they sound quite similar. But their purpose is quite different.
What is RTO?
So, what does RTO mean? BS 25999-2, a leading business continuity standard, defines RTO as &#8220;&#8230;target time set for resumption of product, service or activity delivery after an incident&#8221;.
This actually means that RTO is crucial [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2012/01/30/what-is-the-difference-between-recovery-time-objective-rto-and-recovery-point-objective-rpo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do you really need a consultant for ISO 27001 / BS 25999 implementation?</title>
		<link>http://blog.iso27001standard.com/2011/12/06/do-you-really-need-a-consultant-for-iso-27001-bs-25999-implementation/</link>
		<comments>http://blog.iso27001standard.com/2011/12/06/do-you-really-need-a-consultant-for-iso-27001-bs-25999-implementation/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 11:09:54 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[BS 25999-2]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[training & awareness]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1489</guid>
		<description><![CDATA[
			
		
		ShareI&#8217;ve met quite a few companies considering how to start their ISO 27001 / BS 25999 project, with quite different approaches – some are convinced they can do it completely on their own (with no prior ISO 27001 knowledge), while others thought they can do it with the help of a consultant only.
They are both [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2011/12/06/do-you-really-need-a-consultant-for-iso-27001-bs-25999-implementation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 27001 risk assessment &amp; treatment – 6 basic steps</title>
		<link>http://blog.iso27001standard.com/2011/11/22/iso-27001-risk-assessment-treatment-%e2%80%93-6-basic-steps/</link>
		<comments>http://blog.iso27001standard.com/2011/11/22/iso-27001-risk-assessment-treatment-%e2%80%93-6-basic-steps/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 09:12:52 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=1484</guid>
		<description><![CDATA[
			
		
		ShareRisk assessment (often called risk analysis) is probably the most complex part of ISO 27001 implementation; but at the same time risk assessment (and treatment) is the most important step at the beginning of your information security project – it sets the foundations for information security in your company.
The question is – why is it [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2011/11/22/iso-27001-risk-assessment-treatment-%e2%80%93-6-basic-steps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

