Getting Audit-Ready — ISO 27001, SOC 2, Cyber Essentials
A customer has told your company it needs ISO 27001, SOC 2 or Cyber Essentials, and given you a date. This segment takes you from that email to a scoped, honestly-documented, evidenced position — and a gap assessment of your own organisation you can hand to a finance director.
- trending_upIntermediate
- schedule7h 17m
- menu_book12個のレッスン
- publicEnglish
- workspace_premiumBasic
ブリーフィング
Nobody chooses to do this. It arrives as a line in a procurement pack, or as a condition on a deal that is already in the pipeline, and it lands on whoever in the company looks most technical. That is usually you. The good news is the thing almost nobody says out loud: a customer's procurement form does what no internal risk register has ever managed. It gets security funded. Every framework in this segment is a funding mechanism as much as a control set, and understanding that is what lets you spend the budget on something real instead of on paperwork. Across four modules you will decide which framework you are actually being asked for and what it costs in weeks, draw a scope boundary small enough to certify and honest enough to mean something, build an asset register that includes the two categories everyone forgets, work out which of your devices fail outright on build alone, and write policy the way that survives an audit — describing the state you are genuinely in today, not the one you would like to be in. You finish with a gap assessment of your own organisation, prioritised, with every remediation costed in effort rather than money, because effort is the number you can actually defend in the meeting. You will need the standard. This segment never reproduces control text from ISO 27001, from the SOC 2 trust services criteria, or from any certification body's course material. Controls are referred to by theme, in plain words. When you get to implementation you have to buy the standard and read the controls yourself — there is no legitimate free copy, and an implementation built on somebody's blog summary is an implementation with holes in it.
コースアウトライン · 4個のモジュール
lockアクセスで解放- 01 Why Anyone Asks You For This3個のレッスン·1h 32m
You are not here because the business wanted to be secure. You are here because a customer would not sign. That is not cynicism, it is the most useful fact you have — it tells you who your sponsor…
- 02 Knowing What You Have3個のレッスン·1h 41m
Every framework in this segment starts in the same place, which is a list of what you have. You cannot protect, patch, scope or evidence anything that is not on a list. The list is boring, it is the…
- 03 Writing It Down Honestly3個のレッスン·1h 35m
Write the policy to the state you are actually in today, then improve it. Read that twice. Everything else in this module is a consequence of it.
- 04 Evidence, Questionnaires and the Gap3個のレッスン·2h 29m
Evidence collected in the week before an audit proves that you collected evidence in the week before an audit. Everything here is aimed at making the evidence a by-product of the work rather than a…
よくある質問
- Getting Audit-Ready — ISO 27001, SOC 2, Cyber Essentialsでは何を学べますか?
- A customer has told your company it needs ISO 27001, SOC 2 or Cyber Essentials, and given you a date. This segment takes you from that email to a scoped, honestly-documented, evidenced position — and a gap assessment of your own organisation you can hand to a finance director.
- 事前の経験が必要ですか?
- Getting Audit-Ready — ISO 27001, SOC 2, Cyber Essentialsを開始する前に、ある程度の事前知識が推奨されます。
- Getting Audit-Ready — ISO 27001, SOC 2, Cyber Essentialsはどのくらいの時間がかかりますか?
- Getting Audit-Ready — ISO 27001, SOC 2, Cyber Essentialsには4個のモジュールと12個のレッスンが含まれています。自分のペースで学習できます。
- アクセスするにはどうすればよいですか?
- Getting Audit-Ready — ISO 27001, SOC 2, Cyber Essentialsは任意の有料サブスクリプションに含まれています。