Sunday, January 19, 2020

ISO 27001




ISO 27001 is a standard for implementing an Information Security Management System(ISMS) for the company.  An ISMS is a framework to manage information security risks.
Idea behind 27001 is you to become proactive, not reactive.
There are 14 domains in ISO 27001:

  1. Information security policy
  2. Organization of information security
  3. Asset management
  4. Human resources security
  5. Cryptography
  6. Physical and environmental security
  7. Operations security
  8. Communications security
  9. Access control
  10. Information systems acquisition, development and maintenance
  11. Supplier relationships
  12. Information security incident management
  13. Business continuity management
  14. Compliance


TLS/SSL Vulnerabilities

POODLE:  The SSL 3.0 vulnerability is in the Cipher Block Chaining (CBC) mode. Block ciphers require blocks of fixed length. If data in th...