Skip to main content
Information security management

Information security management

Search complete. 13 mentions across 8 episodes found for "Information security management".

Sep 23, 2026

Robin Van AekenGUEST
9:02
Firstly, is there's all of the typical stuff that gives big enterprises comfort that even though you're a young startup when you launched in July last year, you've got everything that they would expect to have.
Robin Van AekenGUEST
9:14
So everything you've got around your SLAs and you've got the ISMS set up correctly so that you've got the information security and the data handled and you've got the right encryption and your ways of processing and handling data are fully, fully secure.
Robin Van AekenGUEST
9:26
So some of the ways that we make that a bit easier at Magentic is we say everyone has a single tenant deployment on a specific cloud.
Robin Van AekenGUEST
9:33
We often deploy on the clouds of our customer's side themselves, sometimes via a direct link so that no data even touches the open internet.
Dejan KosuticHOST
14:34
Okay, so let's kind of move the topic to, let's say, more kind of implementation issues.
Dejan KosuticHOST
14:40
So do you think that a company can run, let's say, one security system, whatever it's called, I don't know, ISMS or something else that actually covers several standards? So is it possible actually to...
Dejan KosuticHOST
14:52
integrate everything into one system and then run it as
Aaron LangeGUEST
14:56
such? Absolutely.

12 MINS LATER

Aaron LangeGUEST
26:55
So that was a very positive case.
Dejan KosuticHOST
26:59
Are you saying that it's actually easier to implement C5 if you already have 27001 as a base?
Aaron LangeGUEST
27:06
Absolutely, and the striking part is also if you open up the C5 catalog, which I'm sure you will after this session, the very, very first requirement of C5 is to have an ISMS in accordance with ISO 27001.
Aaron LangeGUEST
27:21
That's the first requirement.
George RyanGUEST
12:33
Yeah, so I guess like Jack says, probably best to Split this up as well, isn't it, into tailoring training and then tailoring the awareness courses as such as well.
George RyanGUEST
12:45
So in terms of the tailoring, the training, it's, again, like Jack mentioned, if you've got an ISMS, then, well, actually, if you're training someone, you're going to want stuff that is ISO-focused as well.
George RyanGUEST
12:56
If you go train them on a completely different framework, like PCI DSS, but you're looking at actually your ISO, then potentially that's not going to be the most relevant.
George RyanGUEST
13:05
Same way like you will find when you're doing PCI DSS, which anyone not aware is the payment card industry data security standard.
Christopher ScottHOST
3:59
So I want to talk about ISO 27001 for a moment, Agata.
Christopher ScottHOST
4:03
The standard defines how to build an information security management system, the ISMS.
Christopher ScottHOST
4:08
It requires context definition, risk assessment, control implementation, performance evaluation, and continuous improvement.
Agata LewkowskaHOST
4:16
Yes, exactly.
Sarah NicastroHOST
23:23
Mm-hmm.
Aymen GatriGUEST
23:25
There is quality management system, there is ISMS, information security management system, and so on.
Aymen GatriGUEST
23:30
What is very important now, exactly in the strategy of implementing AI, we have a strategy, also quality or management system for AI, similar to the quality management system, to the ISMS, the environmental management system, to all these management system.
Aymen GatriGUEST
23:44
So when organization are able to build the governance of management systems for the AI at corporate level, from the highest level, from the management to the usage at the lowest level, that will minimize hugely the risk and give guidelines how you can implement, positively benefit in minimizing the risk.
Sarah NicastroHOST
24:09
Yeah, that makes sense.
Jackie BaekGUEST
10:57
In practice, it first has to define its business model and confirm whether it falls within the filing requirements.
Jackie BaekGUEST
11:08
It then needs to establish ISMS certification and AMA organization and internal controls KYC and suspicious transaction reporting system, appropriate IT infrastructure and sound governance.
Jackie BaekGUEST
11:26
The company then submits its filing, respond to request for further information, undergoes fit and proper review, and made based on on-site inspection.
Jackie BaekGUEST
11:39
So this is not a one-time paperwork exercise.
speaker_0HOST
18:54
But how do we guarantee this incredibly sophisticated machine doesn't eventually just break down and turn back into digital dust?
speaker_1HOST
19:00
The linchpin of this entire ecosystem is how CISO.D links the Pillar01 compliance operating system with a continuous database they call the Living ISMS or Information Security Management System.
speaker_1HOST
19:12
This database automatically tracks the age and validity of your compliance evidence.
speaker_0HOST
19:17
How does that decay mechanism work in practice?
Heather ReedGUEST
12:16
factory employees, and they were running at 115% capacity all the time.
Heather ReedGUEST
12:24
And so when our mothership company said, hey, you have to be part of the ISMS, they gave a lot of pushback.
Heather ReedGUEST
12:33
And it took a lot of relationship building to get to the point where they trusted me well enough to know that that ISMS was not going to be a burden on them.
Heather ReedGUEST
12:45
That's what they were worried about.
Heather ReedGUEST
12:47
We don't have time for more work.
Heather ReedGUEST
13:20
I had visibility to obviously the incidents that were occurring.
Heather ReedGUEST
13:25
So I just started approaching it from more of like what I can do for you instead of what you can do for me.
Heather ReedGUEST
13:31
So, you know, I volunteered to have my team take on the heavy lifting of getting them into the ISMS, making sure that everything was documented.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.