Join us for a Free webinar, hosted by an International
ISO Auditor. This is a rare opportunity to understand where ISO Auditors are
approaching the audits. External Auditors are not allowed to provide any advice
during an audit or to provide consulting to audit clients. Thus, we are just
auditing to make a judgement regarding the compliance against the requirements
of the standards.
This webinar will address the practical process of
conducting a practical Gap Assessment, based on the international Best practice
as stipulated in ISO 21827, the Capability Maturity Model (CMM) and what auditors are looking for:
1. Start With the Right Assessment
Question
1.1 The two questions
1.2 Why use both
1.3 Practical status categories
2. ISO/IEC 21827 Assessment
Architecture
2.1 Two dimensions
2.2 Model structure
2.3 Core security-engineering process areas
3. Capability Levels and Assessment
Criteria
3.1 The cumulative rating rule
4. Plan the Gap Analysis Before
Collecting Evidence
4.1 Recommended assessment file
5. Conduct Fieldwork: Evidence Before
Opinion
5.1 Evidence methodologies
5.2 Triangulation rule
5. Worked Example: Assess Security Risk
6.1 Finding statement
6.2 Recommended actions
7. From Findings to a Prioritised
Roadmap
7.1 Minimum finding fields
7.2 Prioritisation model
8. Professional Gap Analysis Report
Layout
8.1 Reporting cautions
9. Recommended Slide Deck Layout
10. Facilitator Guidance and
Interaction
10.1 Opening script (approximately 60 seconds)
10.2 Participant prompts
10.3 Five closing takeaways
11. Source Materials and Development
Notes
12. Contact us