Crest Advisory Africa: A Trusted Partner for MSECB and PECB Services

Obtain an ISO certification that affirms you are compliant with the world’s best-known practices and most widely used standards!
Managing Disruption: The Importance of Business Continuity Management (BCM)

Business Continuity Management (BCM) is a proactive approach to managing disruption, helping businesses prepare for, respond to, and recover from disruptive events.
Crest Advisory Africa Attains PECB Platinum Level Partnership: A Milestone in Providing Exceptional Information Security and Risk Management Services

Crest Advisory Africa (Pty) Ltd attains PECB Platinum Level as an Authorised Partner, offering clients access to top information & services in information security & risk management. Get in touch to learn how Crest Advisory Africa can help improve your business. #PECBPlatinumLevel
What is Risk?

What is risk? There’s a lot of research into all types of risk, but in my experience, I have found that most people and organisations don’t completely grasp the concept. In this article, I will try and cut through the fancy words and “businesslese” (the formal and technical language of business governance documents) and answer […]
Book your Human Rights Audit for 2023

Book Your Human Rights Audit or Training.
7 Critical Steps to Pass Audits

There are 7 Critical Steps to Pass Audits. Carina takes your through these steps.
BIA – How to Structure the Resource Analysis for a Business Impact Analysis

Introduction One of the processes within the Business Continuity Management System (BCMS) is the development of a Business Impact Analysis. I have experienced several companies that are struggling with this process and this concept. In this article, I will explain the structure of one of the sections within the BIA process. This structure is analysing […]
The ERM Risk Matrix: Modelling Fault

Introduction Enterprise Risk Management (ERM) is describing a Risk Matrix (ERM Risk Matrix) as a tool for ranking and displaying risks by defining ranges for consequence and likelihood. This is a very easy concept if one knows how to develop matrixes, and this is where the catch is. Over the 35 years, where I have […]
What is a Management System?

Alexander Venske explains the basics of a Management System.
March 2022 – From the desk of the CEO

Crest Advisory Africa and its international growth strategy.
ISO 37301:2021 — Building and Maintaining a Culture of Compliance

In a world of global business activity, following requirements and complying with applicable laws is becoming an increasingly complex endeavour. The demand on business enterprises to behave in step with the law is increasing. In this light, stakeholders are more aware of the regulations and their requirements, and expect organizations to ensure compliance along the […]
Migrating from ISO 19600:2014 to ISO 37301:2021

What is a Compliance Management System (CMS)? For organizations seeking growth and long-term success, adhering to compliance obligations is not an option, is a must. Failing to comply with laws and regulations could mean losing millions in fines, or worse, damaging the organization’s reputation in the global marketplace. ISO 37301:2021 is a Type A management system standard […]
Why integrating ISO9001, ISO27001 & ISO22301 is important for your business security?

What should your customers know about? Hi, my name is Devesh Pandit, and I represent E4 Security Consulting, we are based out in the USA. When I talk to my customers I talk to them about their responsibility in terms of quality, providing a quality product, secure product and has built-in business continuity. So, to […]
How can an effective Disaster Recovery Plan help your business?

A disaster recovery plan incorporates the protection measures taken to reduce the impacts of a disaster so that an organization will be able to preserve or swiftly restart their IT systems.
Reduce the risk of project failure with ISO 21500

Project management in an inseparable part of organizations in today’s fast changing global economy.
ISO 22000 Food Safety Management Systems (FSMS)

Global food production has been confronted with some troubling results in the last decades.
ISO 13485:2016 Suitable for Modern Medical Devices Industry

Bribery refers to any offering, giving, accepting or promising advantage with any value or bribe in order to influence the decision, action or judgement of persons in charge of a duty.
ISO 14001 Certification – Guidance to Protecting the Environment

Bribery refers to any offering, giving, accepting or promising advantage with any value or bribe in order to influence the decision, action or judgement of persons in charge of a duty.
Why ISO 31000 is important to organizations nowadays?

Risk analysis, we do it every day. But when it comes to risks that occur in companies, a more formal approach is required.
Incident Management as a Requirement of ISO 18788

What is ISO 18788? ISO 18788 specifies the requirements and provides guidance for organizations that conduct or contract security operations.Moreover, it provides a framework for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a Security Operations Management System. It enables the constant development of security services while ensuring customer safety and respect for human rights. […]
Business Continuity: From a Best Practice to a Priority Objective

The COVID-19 pandemic has changed the global business environment. During various global implementation practices for managing the pandemic, we were the audience to experience various lockdown regulations, businesses who had to make difficult decisions regarding cash flow, retrenchment of staff, placing of people on furlough and in severe circumstances, the closing down of businesses, etc.Some […]
The importance of implementing a BCMS based on ISO 22301 in order to ensure the continuity of businesses operations

The COVID-19 Pandemic has changed the global business environment. During the various global implementation of managing the pandemic, we were the audience in receiving the various lockdown regulations, the businesses who have to make hard decisions regarding cash flow, the retrenchment of staff, the placing of people on furlough and in severe circumstances, the closing […]
Corruption, Corruption, Bribery, Bribery: The Non Violent Killer of a Society

COVID 19 has brought about hardship for millions of people across the world. In an article I wrote for the PECB for their PECB Insights Magazine, I have addressed Business Continuity, Risk Bearing Capacity (RBC) and Cloud Security. Today I am going to address Bribery and Corruption. These two issues are dear to my heart, […]
ISO 27701: 2019: PIMS: International Certification to protect Personal Identifiable Information (PII)

Over the past two years the PII environment has changed exponentially. With the introduction of General Data Protection Regulation (GDPR) from the European Union and its enforcement beginning on May 2018, the importance of data protection collected from organizations for a variety of reasons is becoming the utmost objective of each organization and involved individuals. […]
International Medical Devices Industry: FDA to Transition to ISO 13485

The U.S. Food and Drug Administration has announced that it will transition to ISO 13485:2016 after conducting a comparative analysis between the latter and the current Quality System Regulation (QSR). In an official update from the FDA in December 2018, the reasons for and benefits of implementing ISO 13485 as the benchmark for quality management system […]
A Beginner’s Guide to Network Segregation

Information Security Management Network segregation is the tool used for dividing a network into smaller parts which are called subnetworks or network segments. You can think of it as the division of rooms when constructing a new house. The most important things to spend time thinking about in this case are the spacing and positioning […]
Data Controller VS. Data Processor and ISO/IEC 27701

Information Security Management The popularity of the terms “data controller” and “data processor” has sharply increased in recent years. In part because of the significant increase of data breach scandals from tech giants, and in part because of the unprecedented media attention is given to the enactment of data privacy regimes (such as the EU General […]
ISO 31000:2018-Risk Management Guidelines

The ability to predict what the future holds and choosing effectively among varying alternatives lies at the centre of contemporary societies and organizations. Risk management guidelines can help us navigate over a broad range of decision-making processes, from making investment decisions to safeguarding our health, from waging war to planning families, from paying insurance premiums […]
ISO/IEC 27001 Certification Provides the Concrete Benefits

Introduction Corporate data breach reports constantly hit new headlines, which serve to remind us that nowadays our information is unsecured more than it’s ever been before. In 2015, data breaches, cybercrimes, and hacking were top business issues that garnered much media attention and compromised the integrity of many companies. According to research, no industry – […]
ISO 22000 – What the Future Holds for Food Safety

“Food Safety” refers to the prevention, elimination and control of foodborne diseases at the stage of consumption. In a globalized world, the impact of food safety hazards and foodborne diseases on customers’ health and well-being has raised many questions: Is the food that we eat safe? How can we ensure food safety? One thing is […]
Building a Successful Recruitment Plan with Crest Advisory Africa

Hiring the right employees for your business is important no matter what kind of work you’re in. Having quality employees will help your company run and grow. However, it can be a daunting task to recruit and keep top talent. Reviewing resumes and browsing profiles is only part of the job. Hiring managers need to […]
Return on Investment (ROI) Using Plan-Do-Check-Act (PDCA) Methodology

Introduction Crest Advisory Africa Pty Ltd (Hereafter CAA) is a Global Management System Consultancy working with diverse entities, whether private or public, to improve and grow the business we are working with to at least have a 33% to a maximum of 200% increase on their profitability. CAA’s blueprint in changing businesses around is based […]
Reduce the Risk of Project Failure with ISO 21500 Project Management

Project management is an inseparable part of organizations in today’s fast-changing global economy. Its practices began a century ago, but it became an essential factor of successful organizations only in the past few decades. Managing projects efficiently is crucial for organizations that want to overcome obstacles and achieve their goals and objectives. According to ISO 21500, […]
How can Six Sigma Benefit your Organization?

Six Sigma Benefits Reducing Waste Improving Time Management Increase Customer Loyalty Boost Employee Motivation Higher Revenues and Lower Costs Six Sigma has proven to be a very successful tool for organizations seeking to identify problems, remove roots of errors or failures, and improve their business processes. Since its conception in 1986 by Motorola Company, Six Sigma has […]
ISO 50001: A Perfect Match for Energy Efficiency

As the threat of energy-resource depletion has emerged, the global demand for energy is increasing constantly. Provided that billions of people still have no access to electricity, more energy will be needed in the future to improve the living standard by constructing industrial, commercial and transportation infrastructure. With this future looming, it is of utmost […]
Essential Key For Data Protection: ISO 27001

Is your Business protected against a breach of data and software? Are you Internationally Certified to be able to prevent hackers from stealing your organization’s valuable data? Businesses understand the importance of security. They lock their doors, install alarms, and hire security guards. Unfortunately, too many of them don’t give their data security the same […]
Business Continuity Management System (BCMS) Business Impact Analysis (BIA) Understanding the Business Impact Criticality / Materiality

Business continuity plan involves the employment of time and resources in analysing the functions within the organization, and thus assess their criticality. First of all, it is crucial to analyse critical and essential functions of the business. Criticality and Materiality are a term haphazardly used in business. How is this measured and how does this […]
How to Apply Proper Risk Management Methodology on Information Security?
How to apply proper risk management methodology on information security? Risk in its negative way might be defined as one undesired consequence that may or may not occur, as a result of specific outcome we want to achieve. Shortly, it is the effect of uncertainty on objectives, as defined in ISO 31000. Many organizations are exposed to […]
Benefits of Implementing ISO 37001 in an Organization

Bribery refers to any offer, giving, accepting or promising advantage with any value or bribe in order to influence the decision, action or judgement of persons in charge of duty. Any individual or organization that is involved in bribery means that they have accepted or given something with the intention of influencing the recipient in […]
Key Steps for an Effective ISO 27001 Risk Assessment and Treatment

In view of the developments that have occurred in the processing, storage and sharing of information; security has become an important aspect of an organization. It has become more imperative for an organization to understand the various threats and risks facing them as they seek to protect their information. The rapid development of new technologies […]
Online Learning | Beyond the Classroom

The education industry has gone through tremendous changes over the last decades in terms of educational opportunities, teaching methods, availability of reading materials, etc. With the advancements in technology and availability of the Internet, there has been a shift from in class to online learning. This shift was accompanied by the necessity to standardize the […]
Profit, People & Planet with ISO 20121
The Three P(’s)illars of Sustainability The concept of the “triple bottom line” was firstly introduced in 1994 by John Elkington, with the idea of organizations preparing three different bottom lines in order to measure their financial, social and environmental performance. The first bottom line stands for the traditional measure of corporate profit, specifically for the profit […]
Marriot’s’ 500 Million Data Breach Scandal
A politically inclined attack or just a ‘simple’ lack of security awareness? Whatever the case, the cyber-attack that hit Marriott was huge. This was the joint second largest data breach to take place, after Yahoo in 2013 and Equifax in 2017. A cyber attacker stole personal information including names, emails, addresses, passport numbers, and credit card information […]