Visualização normal

Ontem — 9 de Setembro de 2026Stream principal

Should access review changes go through normal ticketing, or is the review spreadsheet enough evidence?

9 de Setembro de 2026, 06:23

Fairly large org, some high-risk systems. To get access (or a change to access) requires a ticket and approval from your manager/

  1. Separately, we run access reviews twice a year:
  2. Reviewer sends the current access list (Excel) to managers.
  3. Managers markup changes, e.g. "user left, remove access" or "needs modified access."
  4. Reviewer makes those changes directly on the system.
  5. Question: During these reviews should managers (or the reviewer, on their behalf) raise a proper ticket for these changes and note the ticket number on the sheet, rather than the markup alone on the excel sheet triggering the change?
  6. My take: yes, the manager should raise a ticket as ultimately it is a change request. However, I do accept the spreadsheet does show a manager requested a change.
  7. How do others handle this, same ticket/approval workflow as normal requests, or is the review sheet treated as sufficient on its own?
submitted by /u/Efficient_Bus_923
[link] [comments]
Antes de ontemStream principal
  • ✇cybersecurity
  • Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing /u/Efficient_Bus_923
    I am assessing a vendor that holds ISO 27001:2022. They are a development company who sell a software product and plugins, deployed on an AWS instance per customer. When asked about penetration testing, they indicated they only do customer-specific testing. I want to push back and ask questions around ISO 27001 control 8.29 - Security testing in development and acceptance, to verify they are actually testing the core platform and codebase. What questions should I be asking that would expose obvi
     

Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing

8 de Junho de 2026, 08:04

I am assessing a vendor that holds ISO 27001:2022. They are a development company who sell a software product and plugins, deployed on an AWS instance per customer. When asked about penetration testing, they indicated they only do customer-specific testing. I want to push back and ask questions around ISO 27001 control 8.29 - Security testing in development and acceptance, to verify they are actually testing the core platform and codebase. What questions should I be asking that would expose obvious gaps in their secure development practice and give an indication of the standard of their ISO 27001 audit?

submitted by /u/Efficient_Bus_923
[link] [comments]
  • ✇cybersecurity
  • ISO 27001 Surveillance audit vs Full recertification /u/Efficient_Bus_923
    I'm conducting a third-party risk assessment for onboarding a vendor. Based on the nature of the data they will process and the business criticality of the service to the organisation, I have categorised this as a high-risk onboarding. They've provided their ISO 27001:2022 certificate, which is currently in a surveillance audit year rather than a recertification year. Is a surveillance audit materially less assurance than a full recertification for third-party risk purposes, or are both broadly
     

ISO 27001 Surveillance audit vs Full recertification

4 de Junho de 2026, 07:59

I'm conducting a third-party risk assessment for onboarding a vendor. Based on the nature of the data they will process and the business criticality of the service to the organisation, I have categorised this as a high-risk onboarding.
They've provided their ISO 27001:2022 certificate, which is currently in a surveillance audit year rather than a recertification year.

Is a surveillance audit materially less assurance than a full recertification for third-party risk purposes, or are both broadly equivalent? Is it something that should concern me, onboarding an inherently high-risk platform that does not do full recertification audits?

submitted by /u/Efficient_Bus_923
[link] [comments]
❌
❌