News & Resources

Risk Matrix Modelling Fault

Enterprise Risk Management (ERM) is describing a Risk Matrix[1] as: tool for ranking and displaying risks by defining ranges for consequence and likel...

What is and how to conducts an Adequacy and effectiveness perspective rating

In the context of combined assurance, the statement emphasizes the importance of evaluating and rating controls within an organization using both inte...

Ensuring Compliance and Continuous Improvement: Implementing Internal Audits in ...

Internal audits are a critical component of the performance phase in the management of an Information Security Management System (ISMS). Clause 9.2 of...

Precision in Performance: Implementing Monitoring, Measurement, Analysis, and E...

For an Information Security Management System (ISMS) to be effective, continuous monitoring, precise measurement, in-depth analysis, and thorough eval...

From Assessment to Action: Implementing Information Security Risk Treatments in ...

Information security risk treatment is a crucial step in safeguarding an organization's information assets. Clause 8.3 of ISO/IEC 27001:2022 outlines ...

Risk Mastery: Implementing Effective Information Security Risk Assessments in IS...

Conducting regular information security risk assessments during the operations phase is critical for maintaining an effective Information Security Man...

Operational Excellence: Implementing Effective ISMS Operations and Controls

The effective implementation of operations and controls is crucial for the success of an Information Security Management System (ISMS). Clause 8.1 of ...

Documenting Security: Mastering ISMS Documentation for Optimal Implementation Su...

Effective management of documentation is fundamental to the successful implementation and operation of an Information Security Management System (ISMS...

Clear Channels: Ensuring Effective Communication for ISMS

Effective communication is the lifeblood of a robust Information Security Management System (ISMS). Clause 7.4 of ISO/IEC 27001:2022 emphasizes the im...

Raising Awareness: The Cornerstone of Effective ISMS Implementation

Awareness among employees is a critical component of an effective Information Security Management System (ISMS). Clause 7.3 of ISO/IEC 27001:2022 emph...

Supply Chain Risk Assessment Report

As requested by the Client, CAA performed an “Online Supply Chain Risk Assessment (OSCRA)” on a specific site within the Gauteng area. The...

The Sharks are Hunting! - Helplessness to Empowerment

In January 2019 I was introduced to the Chief Executive Officer (CEO) of a medical supply and distribution company. For the sake of respect for the CE...

Get Directions