Fun of reading ISO standards

1656
Fun of reading ISO standards
(Sorry for English, Russian still not supported by Swype for Spica and I was fool enough to try an official version :)

Sometimes I think those ISO guys have some sense of humour.

In some organizations work habits or the main business have led to a specific "culture" within the organization, one which may be incompatible with the security controls.
Yeah, so true. In fact I saw few such companies. Or wait, I rather saw few dozens of them.

Vulnerability type: Organization
Vulnerability example (this means an exploitable weakness): Lack of proper allocation of information security responsibilities
Threat example (this means an evil that might exploit the vulnerability): Denial of actions.

BINGO!! Wan't do a shit unless it's in my job description :)

I don't like reading standards, but these points add some fun to it.
Alt text
Обращаем внимание, что все материалы в этом блоге представляют личное мнение их авторов. Редакция SecurityLab.ru не несет ответственности за точность, полноту и достоверность опубликованных данных. Вся информация предоставлена «как есть» и может не соответствовать официальной позиции компании.
Security Vision
Вебинар · 30.07.2026 · 11:00
Приоритеты по критичности обман?
Десятки тысяч уязвимостей, но опасна лишь одна. Узнайте на бесплатном вебинаре Security Vision 30 июля, как видеть всю инфраструктуру, верно расставлять приоритеты и не срывать SLA.
Участие бесплатное
18+. Реклама. Рекламодатель ООО «Интеллектуальная безопасность», ИНН 7719435412

Vlad Styran

информационно. безопасно.*