Skip to main content
ISO/IEC 27001

ISO/IEC 27001

Search complete. 102 mentions across 66 episodes found for "ISO/IEC 27001".

Sep 21, 2026

Tim MartinoGUEST
40:40
And I'm trying to remember all the sections off the top of my head.
Tim MartinoGUEST
40:44
But this is the main place for any audit report to request from SOC, PCI, DSS, ISO 27001, and others that we undergo.
Megan BillingsleyMODERATOR
41:00
Perfect.
Megan BillingsleyMODERATOR
41:00
Thank you so much.
Noel BradfordHOST
6:18
ISO 42001 is a voluntary AI management standard.
Noel BradfordHOST
6:22
It's related in spirit to ISO 27001, but it focuses on how an organization governs AI.
Noel BradfordHOST
6:30
It asks useful questions.
Noel BradfordHOST
6:32
Which systems do you use? Why? Who owns them? What data enters them? What decisions do they influence? How do you handle performance, bias, security, human oversight, and review? All the questions
Muhammad AtifGUEST
22:31
HIPAA covers many other things as well, right? So this is one of them that you need to have audit trail.
Muhammad AtifGUEST
22:37
The thing is that working with this enterprise, I mean, we are ISO 27001 certified as well.
Muhammad AtifGUEST
22:42
That is a security protocol for delivering the secure applications.
Muhammad AtifGUEST
22:46
And it has its own processes that need to be deployed, that how employees are going to interact with the data.
Muhammad AtifGUEST
24:32
And on top of that, here at PureLux, we also follow WCH security protocol, again, which is Web Content Accessibility Guidelines.
Muhammad AtifGUEST
24:41
And specifically when we are working with the AI and we try to have AI governance, we follow NIST framework as well on top of that.
Muhammad AtifGUEST
24:48
So these are some best practices along with ISO 27001 that we follow here.
Muhammad AtifGUEST
24:53
to ensure that we are building secure, reliable application, and we are following all the best practices for accessing or dealing with the data, especially the data which is regulated, are regulated industries where we are dealing it.
Kristi MansfieldGUEST
17:23
Well, I think the main thing that we think about is making sure data governance is in place because when communities or when organizations are sharing data, you have to be really secure.
Kristi MansfieldGUEST
17:38
So we have ISO 27001 accreditation.
Kristi MansfieldGUEST
17:43
We manage data governance right down to the actual variable and who – and what gets shared with whom and how that gets shared, then we manage data sovereignty, not only where data is stored but importantly First Nations data sovereignty because much of this is also supporting First Nations, you know, self-determination as well as community.
Kristi MansfieldGUEST
18:09
Self-determination, when you talk about decisions from the grassroots up, democratisation, and data and evidence is critical as part of that.
Chris WatersGUEST
50:59
One of them is from a data security and data integrity perspective, one of the benefits we get of building on our single instance multi-tenant architecture is it's a very mature, very secure architecture.
Chris WatersGUEST
51:10
We go through security audits, ISO 27001, things like that to make sure that the data integrity is good.
Chris WatersGUEST
51:17
I think when it comes to PII, especially with different jurisdictions, there is no technology solution by itself to those problems.
Chris WatersGUEST
51:26
Those are regulatory and legal problems too.
Sec GuyHOST
1:52
By adopting NIST, a CISO can look the board of directors in the eye and prove that their security strategy covers every phase of an attack lifecycle.
Sec GuyHOST
2:03
Next is ISO 27001.
Sec GuyHOST
2:07
While NIST is a structural guide, ISO is an international standard that you can actually be certified against.
Sec GuyHOST
2:14
Here is a secret that separates the mid-level managers from the global executives.
Matt ConlonGUEST
3:33
So I left.
Matt ConlonGUEST
3:35
I joined a phenomenal company where I helped them get ISO 27001 certified.
Matt ConlonGUEST
3:40
But ultimately felt like I always had this burning need that I wanted to solve that alert overload problem.
Matt ConlonGUEST
3:45
And I started talking to CISOs and security professionals to understand, was it just me? Could I not hack it? Or was this actually a problem? And it turned out that 50% of security leaders wanted to quit and 25% wanted to leave the industry.
Stephen PritchardHOST
16:13
I've ticked this box.
Stephen PritchardHOST
16:14
This meets the requirements of ISO 27001 or the CRA or NIST or whatever bit of legislation or regulation that we want to pick.
Stephen PritchardHOST
16:25
And then you go to the board and say, I've done this.
Stephen PritchardHOST
16:28
Thank you for the million dollars, million pounds, million euros.
Chris ColemanHOST
36:03
Interesting.
Chris ColemanHOST
36:03
In many ways, I think a lot of this maps really well to the software world and how people think about cloud software and different types of security and information compliance there, SOC 2, ISO 27001, where everyone, you learn, we're only going to work with other vendors that are SOC 2 compliant because we need to be SOC 2 compliant and pull it in.
Chris ColemanHOST
36:24
And so it's exciting.
Chris ColemanHOST
36:26
From my perspective, there's aspects of this that are quite exciting because I think it brings a... a modern-day sort of security-forward approach to IoT or forces that change that's been missing for quite a long time as kind of a consistent baseline that folks are following.
KobeHOST
36:10
for sure i've used ai uh cloud code uh my company lets us use it so i use it to create a web app that basically uh lists the cis top 18 control implementation group one and what we have an organization with a what a variable what uh exactly and i showed it to my manager he showed it to the guys and i don't even want to I don't want to talk too much, but I showed it to the people in the upper leadership, and they actually liked it.
KobeHOST
36:36
They want to do more for the benchmark, like ISO 27001, so it helps.
KobeHOST
36:43
I think that's a new word.
KobeHOST
36:44
After that, they told me that they need me not to be too technical, but know what they want and be able to deliver.

56 more episodes mention ISO/IEC 27001.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.