News & Resources

P2ST2 Methodology in Risk Controls

Risk controls are one of the most common processes that needs to be assessed during a risk assessment. Crest Advisory Africa (Pty) Ltd (hereinafter CA...

Unlocking Success: How Internal Audit Strengthens Risk Management for Strategic ...

Risk Management is an internal structure to drive the Strategic Objectives of the company it serves. Thus, the Risk Management function is the custodi...

Risk Management vs Internal Audit

Yesterday I came across a discussion piece in a Risk Managers group that I am a member of. The topic was about the relationship between Internal Audit...

Setting the Course: Crafting Information Security Objectives for ISMS Success

In the ever-evolving landscape of information security, setting clear and measurable objectives is crucial for the effectiveness of an Information Sec...

Aligning Information Security Objectives with Strategic Goals: A Guide for ISO/I...

ISO/IEC 27001:2022, Clause 6.2, emphasizes the need for setting clear and measurable information security objectives that align with an organization's...

Leading the Charge: Ensuring Leadership Commitment for ISMS Success

ISO/IEC 27001:2022, specifically Clause 5.1, emphasizes the role of top management in demonstrating leadership and commitment to the ISMS....

Defining Roles and Responsibilities in ISMS: A Framework for ISO/IEC 27001:2022 ...

In an Information Security Management System (ISMS), clearly defining and assigning roles, responsibilities, and authorities is crucial for effective ...

Aligning the ISMS Policy: A Blueprint for ISO/IEC 27001:2022 Compliance

According to ISO/IEC 27001:2022, particularly Clause 5.2, the ISMS policy must align with the standard's requirements to effectively support the organ...

Crafting an Effective ISMS Manual: A Guide to Compliance with ISO/IEC 27001:2022

An Information Security Management System (ISMS) manual serves as a foundational document that outlines the policies, procedures, and controls impleme...

Understanding the Business Impact Criticality / Materiality

Business continuity plan involves the employment of time and resources in analysing the functions within the organization, and thus assess their criti...

6 Reasons why you should have a Business Continuity Plan

If you're an SME, you're busy making money and keeping daily business under control. The last thing you need is another task, creating something that ...

Mastering Risk Evaluation: How ISOLTX ERMS Enhances Risk Prioritization

The ISOLTX Enterprise Risk Management System (ERMS) is a state-of-the-art software solution that empowers organizations to identify, assess, and mitig...

Get Directions